Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Does typing “please,” or shouting a restriction in all caps, make an LLM reliably obey? Brian Tarbox’s answer in “Say Please (if only as a reminder)” is that a prompt can guide a model’s behavior, but it remains an instruction—not a dependable boundary for high-consequence security. Use prompts to guide, inspection layers to catch problems, and code and permissions to limit what the model can actually do.

Does “please” or all caps make a prompt more secure?

Tarbox’s article does not report a controlled comparison of polite wording, all-caps instructions, or model compliance rates. Its point is practical rather than experimental: the wording of a system prompt may shape ordinary behavior, but it should not be treated as an enforcement mechanism. As Tarbox puts it, “That’s not a control. That’s a request.”

That does not make prompts useless. They can establish tone, set expectations, and help a model handle ordinary, well-meaning requests. But a security design should account for the possibility that the model may not follow an instruction in a particular case. Changing the phrasing from “please don’t” to “NEVER DO THIS” does not, by itself, restrict the model’s access or capabilities.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Tarbox’s sign, guard, and glass analogy

The article separates three layers by what they do and where they operate. The analogy is a way to understand the author’s recommendations, not a claim that every guardrail product behaves alike or that these layers guarantee safety.

#1 Best Overall
Layer Role What it can do
Prompt (“sign”) Instruction in the model’s context Guide behavior and tone, but does not independently enforce a security boundary.
Guardrail (“guard”) Inspection of inputs or outputs Review content through mechanisms such as classifiers, moderation passes, or pattern matching. Tarbox mentions Amazon Bedrock Guardrails as an example; the article does not test it or establish that all guardrails work the same way.
Programmatic control (“glass”) Restrictions and checks outside the model’s instruction-following Limit accessible data and available actions, validate requests in code, and require approval before consequential operations.

Where code and permissions create a firmer boundary

The core design question is not only what the model has been told to do, but what it can do if it ignores those instructions. Tarbox recommends treating permissions and application logic as the practical security boundary:

  • Filter data before it enters context. Apply the user’s permissions before retrieving or supplying information to the model, rather than relying on a prompt to keep unauthorized data private.
  • Expose only necessary tools. Do not give a model capabilities that the task does not require.
  • Use least-privilege credentials. Scope credentials to the minimum access needed for the model’s task.
  • Validate tool arguments in code. Check inputs against application rules before carrying out an action.
  • Put a hard check or human approval before destructive actions. Do not make an instruction in the prompt the only barrier to an irreversible operation.

These controls limit exposure or actions independently of whether a model follows a particular instruction. They reduce risk; they do not establish that every failure mode is eliminated.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to use the distinction in practice

  1. Use the prompt for behavior. Set the model’s role, tone, and ordinary handling expectations in its instructions.
  2. Use an inspection layer where appropriate. Check inputs or outputs for categories or patterns your application needs to review, while treating that layer as an additional check rather than a universal guarantee.
  3. Enforce consequential rules outside the model. Apply access filtering, tool restrictions, credential scoping, argument validation, and approval gates in the surrounding application.
  4. Ask what remains possible if the instructions are ignored. If the model could still read sensitive information or execute a damaging action, the boundary depends too heavily on the prompt.

Tarbox summarizes the division this way: “Use the prompt for behavior. Use guardrails to catch what slips through. Use code for anything you’d lose your job over.” The force of the advice is in assigning different jobs to the layers, not in treating any single one as a complete security solution.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.