sf-preflight
Open source · Apache-2.0 · Salesforce change verifier

Know what your change will set off, before it ships.

sf-preflight is an org-aware verifier for Salesforce pull requests and Agentforce actions. It maps the blast radius through your automation, permissions and data model, generates the tests that matter, and leaves an audit-ready evidence pack.

Get started on GitHub View on npm
$ npm install -g sf-preflight
Works offline on SFDX source. No org credentials needed to get value. Also in VS Code and your AI coding agent.
preflight analyze --base main --head HEAD illustrative output
Changed  Opportunity.Discount__c (field)
Radius   3 objects · 5 automations · 1 permission set

Opportunity (update)
 ├─ before-save flow   Opp_Set_Defaults
 ├─ validation rule    Discount_Needs_Approval
 ├─ roll-up            Account.Open_Pipeline__c
 └─ after-save flow    Opp_Sync_Account
     └─ Account (update)
         └─ trigger ContactSync → Contact → Account ⟲ cycle

HIGH    Account ↔ Contact automation cycle
MEDIUM  Active validation rule references changed field
HIGH    Permission set grants Modify All

4 tests suggested  bulk · recursion · idempotency · validation
Salesforce DevOps has mostly solved “can we deploy this?” It has not solved “can we trust what this change will do in this org?”
38%
of teams name testing bottlenecks as the top blocker to scaling delivery.
43%
apply no extra review to AI-generated changes.
19%
cite failed deployments as a blocker. Deployment is no longer the main pain.
Figures from industry surveys, including Gearset's State of Salesforce DevOps 2026.
See it run

One command on the sample org.

Real output from the repo's sample fixture: two automation cycles, an affected Agentforce action, and the validation rules a change collides with.

Terminal demo of preflight analyze finding automation cycles, an affected agent action and validation-rule collisions on the sample org
And in VS Code

The blast radius graph: the change at the centre, what it sets off around it by distance, risk in colour and recursion drawn. Click any node to open its file.

The sf-preflight blast radius graph in VS Code for a change to Opportunity.Contract_Signed_Date__c, showing the objects, flows, validation rules, roll-up, permission set and agent action it reaches, with two recursion arrows
How it works

From a diff to evidence, in four steps.

01

Read the diff

Point it at git refs or a file list in an SFDX project. Changed files map to components: fields, flows, triggers, classes, validation rules, permission sets, agent actions.
02

Build the org graph

Objects, fields, flows, triggers, Apex, permissions and agent actions become nodes. Edges capture what fires on, writes to, reads, invokes and rolls up to what.
03

Compute blast radius

Walk the order of execution per object and event, follow cascades to a set depth, flag cycles as recursion risk, and cite the file behind every finding.
04

Test and prove it

Generate bulk, recursion, idempotency and validation tests, run them as a check-only deployment, and attach the results to a signed evidence pack.
Features

Execution-layer depth, not another screen tester.

ANALYZE

Offline blast-radius analysis

Runs on SFDX source in your repo. Real Apex parsing with a cross-class call graph. Optional read-only --org context adds record counts, org-only automation, assignments and packages.
TEST

Generated regression tests

Bulk, recursion, idempotency and validation-error tests built with a describe-driven data factory. Validate them against a sandbox as a check-only deployment.
AGENTS

Agentforce action verification

Parses agents, topics, actions and targets. Shows which actions a change affects, whether Testing Center covers them, and what access the runtime user needs. Agent responses stay out of reports.
GATE

Policy and quality gate

A .preflight.json policy decides what blocks a merge. On pull requests it is read from the base branch, so a PR cannot loosen its own gate.
EVIDENCE

Audit-ready evidence pack

One pack per change: author, tests, results and approvals, signed with GitHub artifact attestations. JUnit output for the CI systems you already use.
PRODUCTION

From an error back to its change

Reads failed flows, Apex exceptions and Agentforce action errors from an org, read-only, and traces each to the merged change most likely to have caused it. Then plans a partial rollback that ships as a pull request.
AI AGENTS

Built for coding agents, any model

An agent skill in the open Agent Skills format teaches Copilot, Codex, Cursor, Gemini CLI and Claude to check their own Salesforce changes, and the MCP server gives them the tools. AI-assisted commits are detected and flagged.
EDITOR

In VS Code as you work

Findings in the Problems panel and the blast radius beside your code, refreshed on every save, checkout and pull. Works in Cursor and Code Builder too.
What it catches

The incident that passed every test.

Deterministic rules, each citing the metadata file and the path that produced it. No LLM in the core analysis loop.

Automation cycle across objects (recursion risk) HIGH
DML or SOQL inside a loop in a changed or impacted Apex class HIGH
Permission set grants Modify All, View All, or new delete access HIGH
Deleted component that is still referenced HIGH
Changed field referenced by an active validation rule MEDIUM
Validation rule added on an object that automations write to MEDIUM
Three or more automations on the same object and event MEDIUM
After-save flow updates its own triggering record MEDIUM
One engine, many surfaces

Runs where your changes already flow.

From the editor and the coding agent that writes the change, to the pull request, the pipeline and production. Same engine, same findings everywhere.

CLI

$ preflight analyze --base main --head HEAD
$ preflight tests --validate --org my-sandbox
$ preflight agents
$ preflight agent-tests --org my-sandbox
$ preflight incidents --org prod

GitHub Action

Posts a blast-radius comment on every pull request, uploads SARIF and JUnit, and enforces the quality gate. Make it a required check and DevOps Center honors it too.

VS Code extension

Problems panel, a blast-radius view and order of execution for any object, on every save. Offers the MCP tools to Copilot agent mode. From the VS Code Marketplace or Open VSX.
ext install visparashar.sf-preflight

AI coding agents

One agent skill and an MCP server, for any model: Copilot, Codex, Cursor, Gemini CLI, Claude Code, Agentforce Vibes and other MCP clients.
$ npx sf-preflight skill install
# MCP server for any client
$ npx -y sf-preflight mcp

Claude Code plugin

The skill, the MCP server and a hook that checks each Salesforce file Claude edits, in one install.
/plugin marketplace add visparashar/sf-preflight
/plugin install sf-preflight@sf-preflight

Any pipeline

Guides for GitLab, Azure DevOps, Jenkins, Bitbucket and DevOps Center. Vendor-neutral by design: it complements Gearset, Copado and open-source CI instead of replacing them.
Where it fits

The layer your stack is missing.

Question
Deployment tools
Testing Center
UI test tools
sf-preflight
Moves metadata between orgs
Yes
No
No
No, by design
Checks agent topic and action selection
Emerging
Yes
No
Runs those tests per change
Tests screens and UI flows
No
No
Yes
No
Maps what a change sets off in automation, permissions and data
Limited
No
No
Yes
Generates bulk, recursion and permission tests
Not the focus
No
No
Yes
Broad strokes. Products in this space are changing quickly.

Offline first

The core needs only your repo. Live-org enrichment is additive.

Deterministic

Every finding is explainable and cites its source. LLMs are optional consumers, never in the loop.

Execution semantics

Order of execution, cascades, roll-ups and permissions, modeled in one versioned module.

Vendor-neutral

Embeds in the pipeline you have. Open source under Apache-2.0.
Roadmap

Eight milestones shipped. From the editor to production.

M1 · SHIPPED
Offline blast-radius analyzer
M2 · SHIPPED
MCP server, GitHub Action, SARIF
M3 · SHIPPED
Real Apex parser, live-org enrichment
M4 · SHIPPED
Generated tests, sandbox validation
M5 · SHIPPED
Agentforce action verification
M6 · SHIPPED
Policy gate, signed evidence packs
M7 · SHIPPED
Production incidents, partial rollback
M8 · SHIPPED
Agent skill, Claude Code plugin, VS Code extension

Preflight your next pull request.

Install it, point it at a branch, and see what your change will set off. Or add the VS Code extension and see it as you type.

$ npm install -g sf-preflight
Star on GitHub View on npm
sf-preflight · Apache-2.0 · DCO GitHubnpmVS Code MarketplaceOpen VSX