Start here. This is the direct spoken answer to practice first.
Overview
A system prompt can guide behavior, but it is not a safe vault or an enforceable authorization layer.
I assume users can infer or extract much of a system prompt from interaction. It must not contain credentials, private user data, hidden tenant information, or security decisions that work only while their wording stays secret. Authorization, validation, rate limits, and tool policy remain outside the model so disclosure does not grant new capability.