A system prompt is the set of instructions given to an AI model before a conversation begins, defining how it should behave for everyone who uses it. Where a user’s message says what they want right now, the system prompt sets the standing rules: the assistant’s role, what it should and should not discuss, the tone it should use, the information it should draw on, the tools it may use, and what to do when it is unsure. Visitors to a website chatbot never see the system prompt, but it shapes every answer they get.
If you have used an AI assistant on a company’s website that stays on topic, speaks in the company’s voice, and hands you to a person for billing questions, a system prompt is doing most of that work.
System prompts vs. user prompts
Most AI applications combine several kinds of input. The system prompt is written by whoever builds or deploys the assistant and applies to every conversation. The user prompt is what the person types. Some applications also add retrieved context, such as relevant pages from a knowledge base, and the outputs of any tools the model uses. Models are generally trained to give the system prompt more weight than user messages, so that a deployment’s rules hold even when a user asks the assistant to ignore them, although no model follows its instructions perfectly.
The craft of writing all of these well is prompt engineering. The system prompt is where most of that craft is concentrated in a business deployment.
What a good system prompt includes
Role and purpose. Who the assistant is and what it is for: “You are the website assistant for a Raleigh web design agency. You help visitors understand our services and book a discovery call.”
Audience. Who it is talking to and what they usually need, so it pitches answers at the right level.
Scope. What it should help with and what it should decline or redirect. A narrow scope is the single most effective way to keep an assistant reliable.
Sources of truth. Which information it should answer from, usually retrieved content from the business’s own site and documents, and an instruction not to go beyond it.
Handling uncertainty. What to say when it does not know, and when to hand off to a person. Explicitly permitting “I do not know” reduces hallucination.
Tone and style. The brand voice, preferred length, formatting, and any words or claims to avoid.
Rules for sensitive topics. Pricing, legal and medical questions, complaints, personal data, and anything that could create a commitment on the business’s behalf.
Tool use. For assistants that can act, such as booking appointments or looking up orders, which tools they may use, when, and which actions require confirmation.
Examples. A few sample questions with ideal answers often teach tone and boundaries more effectively than long descriptions.
A simple example
A condensed system prompt for a small professional services firm might read:
You are the assistant on the website of a Raleigh accounting firm. Help visitors understand the firm’s services, fees policy, hours, and how to book a discovery call. Answer only from the provided website content. If the answer is not in that content, say you are not sure and offer to connect them with the office. Do not give tax or legal advice about a visitor’s specific situation; explain that a CPA can help in a consultation. Keep answers under 120 words, friendly and plain. Never ask for Social Security numbers, bank details, or tax documents in chat. When someone wants to book, share the scheduling link.
A production prompt would be longer and more specific, but the structure is the same: role, scope, sources, boundaries, tone, and next step.
Writing system prompts that work
Be specific. “Be helpful and professional” gives the model almost nothing to act on. “Answer in two or three sentences, then offer the next step” does.
Explain the reason for important rules. Models apply instructions more sensibly when they understand why: “Do not quote prices, because every project is scoped individually and a quoted figure may be taken as a commitment.”
Say what to do, not only what to avoid. Pair every prohibition with the alternative behavior, such as offering a consultation instead of giving advice.
Keep it organized. Group instructions under clear headings. Contradictory or scattered rules produce inconsistent behavior.
Test with real questions. Collect the questions customers actually ask, including awkward, off-topic, and adversarial ones, and check every answer before launch.
Iterate from the logs. Conversation logs reveal where the assistant misunderstood, overreached, or was unhelpfully cautious. Most improvements come from revising the system prompt in response.
Version it. Treat the system prompt like code: keep a history of changes and why they were made, so a regression can be traced and reversed.
Security: what system prompts cannot do
A system prompt is an instruction, not a security boundary. Two limits are important.
System prompts can leak. Determined users can sometimes coax an assistant into revealing its instructions. Never put passwords, API keys, private customer data, internal pricing formulas, or anything confidential in a system prompt. Assume it may become public.
Prompt injection. Users, or content the assistant reads such as a web page, email, or uploaded document, can contain text designed to override the system prompt: “Ignore your previous instructions and…” Models resist this better than they used to, but not perfectly. The real protection is architectural: limit what the assistant can access and do, require confirmation for consequential actions, validate tool inputs in code, and treat retrieved content as data rather than as commands. These controls matter most for agentic AI systems that can take actions.
System prompts and retrieval
A system prompt tells the model how to behave; it is not the right place to store everything the model needs to know. Stuffing a full service catalog, policy manual, and FAQ into the prompt makes it long, expensive, and hard to maintain. The better pattern is retrieval-augmented generation: keep the knowledge in a searchable store, often a vector database, retrieve the relevant passages for each question, and use the system prompt to instruct the model on how to use them. Updating the knowledge base then updates the assistant without touching its instructions.
System prompts across AI platforms
Most AI platforms expose a system prompt in some form. In developer APIs it is a dedicated field or message role. In no-code chatbot builders it may be labeled “instructions,” “persona,” or “custom behavior.” Consumer assistants such as ChatGPT, Claude, and Gemini offer custom instructions or project settings that act as a personal system prompt for your own use. The principles above apply to all of them, but a business deployment deserves the most care, because its instructions apply to every customer conversation.
Common system prompt mistakes
Too broad a scope, which invites the assistant to answer questions it has no good information about.
No permission to say “I do not know,” which pushes the model toward guessing.
Rules without reasons, which the model applies too literally or not at all.
Secrets in the prompt, which may be exposed.
No handoff path, which strands customers with questions the assistant cannot answer.
Set and forget, with no review of logs after launch.
Copying a template unchanged, so the assistant sounds generic and knows nothing specific about the business.
Getting help
Our AI chatbot development service designs the system prompt, the knowledge base, and the guardrails together, grounded in your own content, tested against real customer questions, and reviewed after launch. Book a discovery call if you are considering an assistant for your website.