Skip to content
Road to Intelligence

Concept · Chapter 12: Embeddings, RAG & the LLM Application Stack

System Prompts and Instructions

Must knowKnow well9 minDifficulty

A system prompt is the developer's standing instruction at the start of the conversation (the role, rules, output format and available tools), and to the model it's just more tokens in the chat template that post-training taught it to give priority.

The problem

An application needs consistent behaviour across users (tone, scope, format, which sources to trust), but a chat model starts every conversation with no idea what the application is for.

The solution

Prepend a system message with the task, constraints, format and examples; the model was post-trained to follow such messages and usually to weigh them above user turns.

The consequence

Much application behaviour is set in plain language, cheaply and quickly. But instructions are followed probabilistically, not enforced: they can be ignored, misread or overridden by text later in the context.

Just tokens, in a special place

A chat model sees one sequence. The chat template marks who said what, and the first block usually belongs to the system role. Nothing in the architecture makes those tokens special; post-training on conversations that start with system messages taught the model to treat them as the standing rules of the conversation.

What goes in one

A good system prompt reads like a brief for a capable new colleague:

  • The task and audience: "You answer questions about our API for developers."
  • Constraints: answer only from the provided sources; say when they don't contain the answer; don't give legal advice.
  • Format: length, structure, citation style, or a schema (structured outputs).
  • Tools: what each can do and when to use it (tool calling).
  • Examples: one or two worked exchanges often specify the format better than a paragraph of description (in-context learning).

Prompt wording matters less than it used to as models got better at following instructions, but specificity still matters: "be concise" means different things to different readers; "at most three sentences" doesn't.

Not a security boundary

Instructions are followed with high probability, not enforced. A user can ask the model to ignore them, and text pulled in from a web page or document can contain instructions too (guardrails). Anything that must hold, like "this user can only see their own records", belongs in ordinary code around the model, not in the prompt.

What to remember

  • A system prompt is tokens in the chat template, placed first.
  • Be specific: task, audience, constraints, format, what to do when unsure.
  • Examples (few-shot) often beat descriptions.
  • Instructions are a strong default, not a security boundary.

Watch