System Prompt
A system prompt sets persistent instructions and behavior for a model before the user's messages begin.
Prerequisites
What Is a System Prompt?
Most chat-based LLM APIs accept a small set of message roles — typically system, user, and assistant. The system prompt is the one set by the application developer, not the end user, and it establishes the model's persistent instructions: its role, tone, boundaries, and any rules it should follow for the entire conversation.
System Prompt
Set by DeveloperPersistent instructions, not from the end user.
Conversation History
Prior TurnsEverything said so far in the conversation.
User Message
Current TurnThis turn's actual question.
Model Response
Follows the RulesShaped by the system prompt for the whole conversation.
Key Idea
The system prompt sets the rules of the conversation before the user says anything — think of it as the application's standing instructions to the model.
What Goes in a System Prompt
- The assistant's role — "You are a customer support assistant for a software product."
- Behavioral rules — tone, format, what to refuse, what to always do (like citing sources).
- Constraints — output format, length limits, or language requirements.
- Available context — for example, that the assistant may see retrieved documents and should answer only from them.
Warning
A system prompt is a strong influence on behavior, not an unbreakable rule. A sufficiently adversarial user message — or untrusted text pulled in from elsewhere — can still get a model to deviate from it.
A Real-World Example
Two applications built on the exact same underlying model can behave completely differently just by changing the system prompt — one configured as a terse code-review assistant that only outputs diffs, another as a friendly customer-support bot that always ends with an offer to help further. The model is identical; the system prompt is what shapes it into a specific product experience.
Common Mistakes
Treating the system prompt as unbreakable security
A system prompt shapes behavior strongly but is not a guaranteed security boundary — it should not be the only defense against misuse.
Putting untrusted content in the system prompt
Content that isn't fully trusted — like text pulled from a user upload or a web page — belongs in the conversation as data, not blended into the standing instructions.
Writing an overly long, unfocused system prompt
An unfocused system prompt with contradictory or excessive instructions can confuse the model and produce inconsistent behavior.
Assuming the system prompt is invisible to the user
Depending on the application, users can sometimes get a model to reveal or paraphrase its system prompt — avoid putting secrets in it.
Interview Question
What is a system prompt, and what should and shouldn't go in one?
A system prompt is the standing instruction set by the application, not the end user, that establishes the model's role, tone, and rules before the conversation even starts — separate from the user and assistant messages that follow. It should contain the assistant's role, behavioral rules, and output constraints. It shouldn't contain secrets, since users can sometimes get a model to reveal or paraphrase it, and it shouldn't contain untrusted content, since a system prompt is a strong influence on behavior but not a guaranteed security boundary against a determined adversarial input.
What an interviewer may ask next
- Why shouldn't you treat the system prompt as a hard security guarantee?
- Why would putting untrusted text into the system prompt be risky?
- How can two applications built on the same model behave completely differently?
Explain It in 30 Seconds
A system prompt is the application's standing instruction to the model — its role, tone, and rules — set before the user's messages and separate from them. It shapes behavior strongly but isn't a hard security boundary, so it shouldn't contain secrets or untrusted content. Two apps built on the same underlying model can behave completely differently just based on how their system prompt is written.