S

Salesforce sf data command risk rules

Opt-in review of pinned Salesforce CLI sf data create, update, delete, export and bulk job resume routes; blocks hard delete. It does not re

Opt-in review of pinned Salesforce CLI sf data create, update, delete, export and bulk job resume routes; blocks hard delete. It does not resolve the target org or mediate provider execution.

command.salesforce.sf · v1.0.0 · Other extensions

By Community contributorExternal · opt-inCommand coverage
Protection rules
7
Permission checks
7
Mapped commands
7

Overview

What this coverage does

Opt-in review of pinned Salesforce CLI sf data create, update, delete, export and bulk job resume routes; blocks hard delete. It does not resolve the target org or mediate provider execution.

Key facts

Catalog ID
command.salesforce.sf
Version
v1.0.0
Kind
Command coverage
Category
Other extensions
Protection rules
7
Permission checks
7
Mapped commands
7
Maintainer
Community contributor(community, provenance recorded)
Source commit
3f37b9f
Protection model
External · opt-in
External · opt-in

External coverage. It must be enabled through Guard controls; this page does not activate it.

Stated limits

  • Coverage is limited to the reviewed operations and the surrounding Guard policy.
  • A maintainer profile is not a security certification or an official upstream endorsement.

Command mapping

Every command this extension recognizes, with the catalog default floor Guard applies before workspace policy. Search the table, then open an operation for safe variants and the permission ID.

7 operations · 2 blocked by default · 5 reviewed by default These are catalog defaults, not your workspace policy.

7 operations2 blocked5 reviewed
Default floor

Showing 7 of 7 operations

  • Blocked Guard blocks the command at the pre-action boundary.Critical
    • sf data delete bulk --sobject Account --file ids.csv --hard-delete
    Salesforce hard delete
    Default floor
    Blocked by default. Guard blocks the command at the pre-action boundary.
    Detector mode
    enforce
    What it matches
    Blocks sf data bulk hard deletes, and bulk deletes whose flags come from a --flags-dir directory that could add --hard-delete.
    Permission ID
    command.salesforce.sf.permission.hard-delete
  • Blocked Guard blocks the command at the pre-action boundary.High
    • sf data delete resume --use-most-recent
    Salesforce unbound job resume
    Default floor
    Blocked by default. Guard blocks the command at the pre-action boundary.
    Detector mode
    enforce
    What it matches
    Blocks sf data bulk job resumes without a stable job ID: --use-most-recent, or a --flags-dir directory that could supply it, can attach an earlier decision to a different job.
    Permission ID
    command.salesforce.sf.permission.resume-unbound
  • Reviewed Guard intercepts the command for review before it runs.High
    • sf data delete bulk --sobject Account --file ids.csv
    Salesforce record delete
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Reviews sf data record and bulk deletes, including legacy force:data aliases.
    Permission ID
    command.salesforce.sf.permission.delete
  • Reviewed Guard intercepts the command for review before it runs.High
    • sf data export bulk --query 'SELECT Id FROM Contact' --output-file contacts.csv
    Salesforce bulk export
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Reviews sf data bulk and tree exports and bulk result downloads.
    Permission ID
    command.salesforce.sf.permission.export
  • Reviewed Guard intercepts the command for review before it runs.High
    • sf data delete resume --job-id 750000000000001
    Salesforce bulk job resume
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Reviews sf data bulk job resumes that name an explicit job ID.
    Permission ID
    command.salesforce.sf.permission.resume
  • Reviewed Guard intercepts the command for review before it runs.High
    • sf data update bulk --sobject Account --file rows.csv
    Salesforce record update
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Reviews sf data record updates and bulk update or upsert jobs.
    Permission ID
    command.salesforce.sf.permission.update
  • Reviewed Guard intercepts the command for review before it runs.Medium
    • sf data import bulk --sobject Account --file rows.csv
    Salesforce record create
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Reviews sf data record, file and bulk or tree imports that create records.
    Permission ID
    command.salesforce.sf.permission.create

Tool state mapping

No per-tool overrides are declared. Command defaults above resolve through the workspace Guard policy unless a later policy layer changes them.

Runtime identity

Catalog ID
command.salesforce.sf
Guard enforcement ID
command.salesforce.sf
Source path
contributions/extensions/command.salesforce.sf.json
Contribution digest
sha256…5b35e3

Action classes

Salesforce data command

Technical profile

No independent profile published

This extension has no current independent technical profile. Catalog facts and any legacy launch remain separate and are not presented as profile evidence.

FAQ

Frequently asked questions

Opt-in review of pinned Salesforce CLI sf data create, update, delete, export and bulk job resume routes; blocks hard delete. It does not resolve the target org or mediate provider execution. The listing declares 7 rules and 7 permission checks. 7 operations · 2 blocked by default · 5 reviewed by default. Coverage is limited to these reviewed operations and the surrounding Guard policy.

External · opt-in: External coverage. It must be enabled through Guard controls; this page does not activate it. Enabling state is always controlled through Guard policy, never from this directory.

This listing entered the catalog as a community contribution through a public pull request with recorded provenance. Credit is attribution only. A verified publisher profile and the claim flow verify authority separately; neither is an upstream endorsement or a HOL safety certification.

No. Every listing documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. Review the stated limitations and the exact source tree before relying on any single control.

7 operations · 2 blocked by default · 5 reviewed by default. Examples: sf data delete bulk --sobject Account --file ids.csv --hard-delete (blocked by default); sf data delete resume --use-most-recent (blocked by default); sf data delete bulk --sobject Account --file ids.csv (reviewed by default); sf data export bulk --query 'SELECT Id FROM Contact' --output-file contacts.csv (reviewed by default); sf data delete resume --job-id 750000000000001 (reviewed by default); sf data update bulk --sobject Account --file rows.csv (reviewed by default); sf data import bulk --sobject Account --file rows.csv (reviewed by default). These are catalog defaults, not your workspace policy.

External coverage. It must be enabled through Guard controls; this page does not activate it. Enablement is managed through your workspace's Guard policy and controls — never from this directory. Open the install guidance for the setup flow, then adjust the command coverage for command.salesforce.sf in Guard's policy surface.

The matching action is stopped at Guard's pre-action boundary before it executes, and the decision is recorded with evidence your workspace can review. Exact behavior follows your Guard policy combined with this entry's 7 rules and 7 permission checks.

No. Guard is local-first: interception, decisions, and evidence stay on your machine unless your workspace explicitly configures cloud features. This page is documentation only — it never executes a command or changes protection state.

Guard runs locally alongside the major AI coding agents and MCP-capable harnesses, so this coverage applies wherever Guard intercepts actions. See the supported harness guides at https://hol.org/guard/harnesses for per-tool approval behavior and limitations.

Guard has a free local tier that includes command interception, evidence, and the policy controls this listing documents. Team plans add shared policy, review queues, and audit surfaces. Current plans: https://hol.org/guard/pricing

Open an issue or pull request against the hol-guard repository, where the canonical catalog lives: https://github.com/hashgraph-online/hol-guard Listings are corrected through the same public review process that adds them.

Yes. Community extensions are merged through public pull requests with recorded provenance, and you can claim the publisher page for a contribution you maintain through the Publisher Studio.

The command mapping table is the audit trail for covered commands and catalog default floors. Pair it with the reviewed rule and permission counts, the per-tool state mapping, and the exact source tree linked from View exact source at the reviewed commit. Guard records enforcement decisions with evidence locally, so what ships matches what you reviewed.