Start here. This is the direct spoken answer to practice first.
Overview
External documents and tool results are data even when they contain text that looks like an instruction.
I label retrieved documents, email, web content, files, and tool results as untrusted data and keep their provenance through the workflow. The model is told the task and allowed evidence separately, but I assume a malicious instruction may still influence it. Therefore the application restricts accessible data and tools, validates every action, and requires approval before consequential side effects.