Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add BanibrataChatterjee/AwesomeSalesforceSkills --skill analytics-permission-and-sharinggit clone --depth 1 https://github.com/BanibrataChatterjee/AwesomeSalesforceSkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/banibratachatterjee/awesomesalesforceskills/analytics-permission-and-sharing)<a href="https://agentmods.dev/skills/banibratachatterjee/awesomesalesforceskills/analytics-permission-and-sharing"><img src="https://agentmods.dev/badge/skills/banibratachatterjee/awesomesalesforceskills/analytics-permission-and-sharing/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/banibratachatterjee/awesomesalesforceskills/analytics-permission-and-sharing"><img src="https://agentmods.dev/badge/skills/banibratachatterjee/awesomesalesforceskills/analytics-permission-and-sharing.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00083 | $0.03371 |
| Opus 5 | $0.00042 | $0.01685 |
| Sonnet 5 | $0.00017 | $0.00674 |
| Haiku 4.5 | $0.00008 | $0.00337 |
Grade A, and why
analytics-permission-and-sharing scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 216 lines — stays where its author put it; the contents beside it link to each section on GitHub.
CRM Analytics — Permission and Sharing
This skill activates when a practitioner needs to configure access control in CRM Analytics: granting app access, restricting dataset rows to the running user, wiring up sharing inheritance from Salesforce objects, or assigning and validating Analytics licenses. It produces a working three-layer security configuration and an audit checklist.
Before Starting
Gather this context before working on anything in this domain:
- Verify license assignment first. Without a CRM Analytics Plus or CRM Analytics Growth permission set license assigned to the user, no amount of sharing configuration will let them open the app. Check Setup > Users > Permission Set License Assignments before diagnosing any other access issue.
- The most common wrong assumption is that Salesforce OWD and sharing rules control CRM Analytics row visibility. They do not. CRM Analytics maintains a completely independent security layer. A user with no Salesforce record access can still see every row in a dataset unless an explicit predicate or sharing inheritance is configured on that dataset.
- Platform constraints in play: Sharing inheritance works only for five standard objects (Account, Case, Contact, Lead, Opportunity). When a user has access to 3,000 or more source records, sharing inheritance is blocked and a backup predicate set to
'false'(deny-all) must be provided. Security predicates are SAQL filter strings with a hard 5,000-character limit; column names in the predicate are case-sensitive and must match the dataset schema exactly.
Core Concepts
1. Three Independent Security Layers
CRM Analytics enforces three distinct security layers. None inherit from each other or from Salesforce object-level security:
- Permission Set License (access gate): The user must hold a CRM Analytics Plus or CRM Analytics Growth permission set license. Without it, the user cannot open any Analytics asset regardless of sharing settings.
- App-Level Sharing (asset access): Each CRM Analytics app has its own sharing configuration. Roles are: Viewer (read-only dashboards and lenses), Editor (can modify assets), Manager (can share the app and manage membership). Sharing an app does not grant row access — it only controls which assets the user can see in the UI.
- Dataset-Level Row Security (data visibility): By default, every user with app access sees every row in every dataset in that app. To restrict rows, an admin must configure either a security predicate or sharing inheritance on the dataset. Both mechanisms are opt-in and must be explicitly enabled.
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 216 lines · 83 tokens per session scan A dc33d840b96f
analytics-permission-and-sharing is a skill published in the GitHub repository BanibrataChatterjee/AwesomeSalesforceSkills (3 stars, last pushed 4mo ago), licensed Apache-2.0. It adds 83 tokens to every session and 3,371 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
analytics-permission-and-sharing
Configure CRM Analytics (formerly Einstein Analytics) app sharing, dataset-level permissions, row-level security predicates, sharing inheritance, and license assignment. Trigger keywords: CRM Analytics security, row-level security predicate, dataset permissions, analytics sharing inheritance, Analytics Plus license.…
analytics-adoption-strategy
Use this skill when driving adoption of CRM Analytics (Einstein Analytics) across an org — the Analytics Adoption App for measuring who uses which dashboards, embedding analytics into Lightning pages, pinning dashboards to the Analytics home page, self-service personas, and analytics success metrics. Triggers…
analytics-data-manager
Use this skill when configuring Data Manager in CRM Analytics: enabling objects for sync, scheduling data sync runs, setting up remote connections to external databases, monitoring sync status and error logs, or troubleshooting connected object issues. Trigger keywords: data sync, connected objects, Data Manager, sync…
analytics-dashboard-design
Use when designing or troubleshooting CRM Analytics dashboards — chart types, bindings, faceting, dashboard interactions, mobile layout, and filters. NOT for standard Salesforce reports and dashboards — use admin/reports-and-dashboards-fundamentals. NOT for hand-editing dashboard JSON or a SAQL step — use…
analytics-dashboard-json
Use this skill when editing CRM Analytics dashboard JSON directly to implement advanced bindings, custom SAQL/SOQL step queries, layout changes, step parameters, or cross-widget interactions. Trigger keywords: dashboard JSON, SAQL step, binding syntax, mustache binding, dashboard REST API, widget layout, step limit…
analytics-dataflow-development
Use this skill when building, debugging, or optimizing CRM Analytics dataflows — defining node types (sfdcDigest, Append, Augment, computeExpression, computeRelative, Flatten, dim2mea, sfdcRegister), scheduling runs, handling run failures, and tuning performance. NOT for doing the same transformation in a Data Prep…