Start here. This is the direct spoken answer to practice first.
Overview
Providers expose different message APIs, but the durable design question is which source is allowed to define behavior and which source is only data.
Higher-authority application instructions define the model’s role and constraints, while user instructions describe the current task. Retrieved documents, tool results, and quoted text should normally be treated as data, not as new authority. Exact role names and precedence rules vary by provider, so I follow the provider contract and make the application’s trust boundary explicit.