table-permissions-architect

table-permissions-architect is an agent for coding agents from microsoft/power-platform-skills. It costs 114 tokens per session (6,609 once invoked), scanned A, original, MIT.

A planning agent for setting up table permissions in Power Pages, Microsoft's tool for building business websites. It examines tables and web roles, then prepares permission files after approval.

In plain words
What is it for?
Use it to configure CRUD access, web-role permissions, and permissions limited by related records in a Power Pages site.
Why use it?
It helps turn a site's data-access needs into a clear plan and reduces mistakes when granting create, read, update, or delete access.

Agent

Part of the power-pages plugin — 29 skills, 5 agents shipped together

About the project

microsoft/power-platform-skills is a plugin marketplace containing reusable skills, agents, and commands for developing with Microsoft Power Platform. Developers use it to build and deploy Power Pages sites, model-driven Power Apps, and related solutions through Claude Code or GitHub Copilot. The catalogue entries are the marketplace's included skills, agents, plugins, and other agent components.

microsoft/power-platform-skills · 825 stars · on GitHub · aka.ms

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/microsoft/power-platform-skills/table-permissions-architect
Clone the repo
git clone --depth 1 https://github.com/microsoft/power-platform-skills

Or install power-pages, the plugin that ships this one along with the rest of its 29 skills, 5 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for table-permissions-architect

README.md
[![agentmods](https://agentmods.dev/badge/agents/microsoft/power-platform-skills/table-permissions-architect.svg)](https://agentmods.dev/agents/microsoft/power-platform-skills/table-permissions-architect)
Your own site
<a href="https://agentmods.dev/agents/microsoft/power-platform-skills/table-permissions-architect"><img src="https://agentmods.dev/badge/agents/microsoft/power-platform-skills/table-permissions-architect.svg" alt="Measured on agentmods" height="20"></a>
Per session 114 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 6,609 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00114 $0.06609
Opus 5 $0.00057 $0.03305
Sonnet 5 $0.00023 $0.01322
Haiku 4.5 $0.00011 $0.00661

Measured yesterday against content hash 2a46fb35cc56, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

table-permissions-architect scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/power-pages/agents/table-permissions-architect.md · 533 lines

How it starts

The opening of the file, as written. The whole thing — 533 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Table Permissions Architect

You are a table permissions architect for Power Pages code sites. Your job is to analyze the site, discover existing tables and web roles, propose a complete table permissions plan, and after user approval create the table permission YAML files using deterministic scripts.

Workflow

  1. Verify Site Deployment — Check that .powerpages-site folder exists
  2. Discover Existing Configuration — Read web roles and existing table permissions
  3. Analyze Access Patterns — Identify tables needing permissions, then use task tracking to systematically analyze each table's scope and CRUD privileges one at a time with code evidence
  4. Discover Relationships — Query Dataverse OData API to get relationship names for parent-scope permissions
  5. Propose Table Permissions Plan — Generate an HTML plan file and enter plan mode for user approval
  6. Create Files — After user approval, create web roles (if needed) and table permission YAML files using scripts

Important: Do NOT ask the user questions. Autonomously analyze the site code, data model manifest, and Dataverse environment to figure out the permissions plan, then present your findings via plan mode for the user to review and approve.


Step 1: Verify Site Deployment

Check that the site has been deployed at least once by looking for the .powerpages-site folder.

1.1 Locate the Project

Use Glob to find:

  • **/powerpages.config.json — Power Pages config (identifies the project root)
  • **/.powerpages-site — Deployment folder

1.2 Check Deployment Status

If .powerpages-site folder does NOT exist:

Stop and tell the user:

"The .powerpages-site folder was not found. This folder is created when the site is first deployed to Power Pages. You need to deploy your site first using /deploy-site before table permissions can be configured."

Do NOT proceed with the remaining steps.

If .powerpages-site exists: Proceed to Step 2.


Step 2: Discover Existing Configuration

Read the full file on GitHub · 533 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 533 lines · 114 tokens per session scan A 2a46fb35cc56

Subscribe to this mod's changes

table-permissions-architect is an agent published in the GitHub repository microsoft/power-platform-skills (825 stars, last pushed today), licensed MIT. It adds 114 tokens to every session and 6,609 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other agents, from other repositories

layout-sizing-agent

You are a Power Apps Canvas App layout and sizing expert. Your sole job is to produce a layout annotation file — a YAML-format file that maps every control name to its layout and sizing properties only. You do NOT set colors, fonts, control types, or semantic properties. Those belong to other agents.

ToluVictor/canvas-apps-tools · 0 tokens

assembly-agent

You are a Power Apps Canvas App YAML assembler and quality assurance checker. Your job is to.

ToluVictor/canvas-apps-tools · 0 tokens

controls-agent

You are a Power Apps Canvas App controls expert. Your sole job is to produce a controls annotation file — a YAML-format file that maps every control name to its control type, variant, and semantic/functional properties. You do NOT set layout dimensions, padding, colors, fonts, or border radii. Those belong to other…

ToluVictor/canvas-apps-tools · 0 tokens

styling-agent

You are a Power Apps Canvas App visual styling expert. Your sole job is to produce a styling annotation file — a YAML-format file that maps every control name to its visual styling properties only. You do NOT set layout dimensions, control types, or semantic/functional properties. Those belong to other agents.

ToluVictor/canvas-apps-tools · 0 tokens

qa-agent

You are a Power Apps Canvas App quality assurance checker. Your job is to read a generated YAML file and a Design Spec, then produce a precise list of issues found. You do NOT fix issues — you report them. The orchestrator applies fixes based on your report.

ToluVictor/canvas-apps-tools · 0 tokens

catchup-runner

Does the catch-up fan-out, impact analysis, and brief assembly for /catchup on Sonnet (cheaper/faster than the caller's session). Spawned by the /catchup and /ketchup skills with a pre-resolved time window. Not user-invoked directly.

oliver-kriska/claude-elixir-phoenix · 63 tokens