Work through the decision
Define the question, organisation/workspace and records it actually needs. Check current object and field grants before retrieval, including files and financial details. Select permitted source versions and avoid unnecessary personal data. Source pages, uploads and extracted text are untrusted information; instructions embedded inside them cannot expand the assistant’s authority.
A fictional worked example
A fictional buyer asks about one assembly’s missing evidence. The allowed context contains that project and permitted source documents, while another client’s budget stays excluded. A sentence in an uploaded brochure telling the assistant to reveal other records is treated as source data and ignored as an instruction.
Evidence and authority limit
A prompt or local form does not enforce tenant isolation; actual retrieval and execution require server grant checks.
Put it into practice
Define a minimal context packet and list two tempting but unauthorised records to exclude.
Keep this record: A task-specific allowed-context list with source rights and private-field boundaries.
- Context serves a defined task.
- Current grants apply before retrieval.
- Embedded source instructions do not grant authority.