Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Afls Implementation Review

ASecurity

Reviews an AFLS / Life Sciences Cloud implementation against field-observed anti-patterns that cause production incidents and blocked go-lives — sharing model, sample/inventory, mobile sync, over-customization, territory realignment, data/MDM, Agentforce scoping, and UAT/go-live discipline. Use when the user asks to review, assess, health-check, or de-risk an implementation or design; is planning a go-live; is deciding whether to add a custom object or change an OWD/permission; or is diagnosi...

2 stars
0 votes
0 copies
0 views
Added 9/19/2026
ai-agentsrustgorailsapi

Works with

api

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add SalesforceLabs/afls-for-claude --skill afls-implementation-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Afls Implementation Review?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Afls Implementation Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/salesforcelabs-afls-implementation-review/badge)](https://www.skillsdirectory.com/skills/salesforcelabs-afls-implementation-review)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: afls-implementation-review
description: Reviews an AFLS / Life Sciences Cloud implementation against field-observed anti-patterns that cause production incidents and blocked go-lives — sharing model, sample/inventory, mobile sync, over-customization, territory realignment, data/MDM, Agentforce scoping, and UAT/go-live discipline. Use when the user asks to review, assess, health-check, or de-risk an implementation or design; is planning a go-live; is deciding whether to add a custom object or change an OWD/permission; or is diagnosing a post-go-live incident (Sev-1, API limits, duplicate records, inventory-count failures). Also use proactively when a proposed configuration matches a known anti-pattern.
---

## What this skill covers

Catching **implementation design decisions** that repeatedly cause AFLS
production incidents, blocked go-lives, and eroded trust — *before* they ship.
The recurring root cause is trial-and-error configuration against AFLS's
**opinionated, pre-built data model** without validating consequences in a
production-like sandbox.

The authoritative content is the anti-pattern catalog. Load it first:

```
get_afls_troubleshooting({ topic: "implementation-anti-patterns" })
```

For background on any specific area, also use
`search_afls_knowledge({ query: "..." })`.

## When to activate

- The user asks to **review / assess / health-check / de-risk** an implementation or a proposed design.
- The user is **planning a go-live** or asking "are we ready?".
- The user proposes a change that **matches a known anti-pattern** — flag it proactively:
  - Changing an **OWD** (especially Visit) to Public/Controlled-by-Parent.
  - Granting **"View All" / "Modify All"** on Visit, ProductDisbursement, or inventory objects.
  - Adding a **custom object** or a **non-standard screen** that shadows standard AFLS objects.
  - Proposing **OmniStudio** for anything in the **mobile** scope (it is web-only).
  - Setting a **very short mobile sync interval** or enabling **attachments on every DB Schema record**.
  - Rolling out **Agentforce** before the data foundation / MDM is ready.
- The user is **diagnosing a post-go-live incident** (Sev-1, API-limit "death loop", duplicate visits, reps unable to submit inventory counts). Treat these as **config/design issues first, product bugs last** — historically ~90% are config/knowledge gaps.

## How to run a review

1. **Load the catalog** (`get_afls_troubleshooting({ topic: "implementation-anti-patterns" })`) and work its **Pre-Go-Live Review Checklist**.
2. **Inspect the live org where possible** rather than asking. Useful tools:
   - Sharing/visibility & permissions → `describe_sobject`, `list_permission_sets`, `check_user_config`.
   - Mobile sync & cache → `list_db_schema` / `get_db_schema` (attachment flags, SOQL filters), `check_mobile_cache_status`.
   - Data model bloat → look for custom objects shadowing standard ones (`Visit`, `ProductDisbursement`, `ProviderVisit`, etc.).
   - Territory → `check_territory_config`.
   - Overall → `health_check`, `get_org_status`.
3. **Map findings to anti-patterns.** For each finding, state: the pattern, why it fails on the AFLS data model, and the correct approach — straight from the catalog.
4. **Prioritize by go-live risk.** Sharing-model and mobile-sync issues that can cause Sev-1 or block regulated reporting rank first.
5. **Recommend remediation before go-live, not after.** If several checklist items fail, say plainly that the program matches the recurring failure profile and remediation should precede go-live.

## Guardrails

- **Never widen access as a first resort.** Before any OWD change or "View All" grant on a core AFLS object, establish what platform logic depends on that object's ownership/sharing (inventory counting keys off ProductDisbursement ownership; Visit is designed to be Private).
- **Default to standard config.** Require a written justification for each custom object; prefer standard layouts/actions.
- **OmniStudio is web-only** — never propose it for mobile/iPad.
- **UAT on a full-copy sandbox on production's release, with production-scale data.** Off-release or partial sandboxes hide exactly these defects.
- These lessons are **de-identified and generalized** — describe the pattern and the fix, not any customer or partner.

## Related

- `afls-troubleshoot` — symptom-driven module troubleshooting.
- `afls-health-check` / `/afls:health-check` — config-completeness verification.
- `afls-config-migration` — safe promotion of config between orgs (revert experiments; don't migrate everything).
- Catalog: `knowledge/troubleshooting/implementation-anti-patterns.md`.

Attribution

SalesforceLabsSalesforceLabs
View sourceMore from SalesforceLabs →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693621 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →