Zero-shot: instructions only. Works for common tasks if the instructions are clear: say what to do, for whom, in what format, and what to do in edge cases. Few-shot: add 2–5 input→output examples. They teach format and subtle judgement better than descriptions, but choose diverse, representative examples, because models copy their quirks.
Use delimiters (XML-style tags like <document>…</document> work very well) to separate instructions from untrusted data. This improves accuracy and is a first layer of defence against injection.
The system prompt sets the role, rules and context that persist; the user turn carries the task. Explain why a rule exists; models follow reasoned instructions more robustly than bare commands.
System: You classify customer emails for a support team.
Categories: billing, shipping, account, other.
If an email fits several, pick the one the customer needs resolved first.
User: <email>
I was charged twice and my package still hasn't arrived.
</email>
Return only the category name.Going deeper
Order matters for long prompts: put long documents first and the question and instructions at the end. Models often follow end-of-prompt instructions more reliably at long context.
Tell the model what to do instead of what not to do ('respond in plain prose paragraphs' beats 'don't use markdown'), and explain the reason for unusual constraints.