Start here. This is the direct spoken answer to practice first.
Overview
The safest sensitive token is the one the feature never sends, stores, embeds, or logs.
I define the task and send only the fields needed to perform it. Context is built from allowlisted sources and fields rather than copying an entire record, conversation, or document store. Where the task permits it, I redact, tokenize, aggregate, or pseudonymize identifiers before the model call and restore references only inside the trusted application boundary.