---
title: 'System prompts and models'
description: 'The Settings › Model defaults screen in Studio: the prompt and the model of each model caller Stackbone runs inside your box, with a reset back to what ships.'
position: 20
---
# System prompts and models
> Stackbone makes model calls of its own inside your **box** (the container
> running your workspace, or `stackbone dev` on your laptop). The Studio copilot
> answers you, a guardrail asks a model about a turn, an eval grades an answer.
> **Settings › Model defaults** in Studio gives each of these callers one card, with the
> text it frames its model with and the model it runs on. Every card starts on
> what Stackbone ships, and a reset goes back to it.

_The first two cards. The copilot card links to its catalog entry. The classifier card edits its prompt in place._
## The five callers
| Caller | Where you edit its prompt | Where you pick its model | What the prompt controls |
| -------------------- | ---------------------------------------------------------------------------------------------------- | ------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------- |
| Studio copilot | The **Prompts** block of its catalog entry, key `instructions`. The card links there. | The **Models** block of its catalog entry | Its whole system prompt: how it talks and works. Its tools, and the screen you have open, reach it separately. |
| Guardrail classifier | Its card | Its card | How the model is framed when a guardrail asks it about a turn (prompt injection, harmful content, off-limits subjects). |
| Eval judge | Its card | Its card | The stance of the model that grades an answer against a rubric criterion. |
| Persona simulator | Its card | Its card | How the model is framed when it plays the user in an eval case that asks a question back. |
| Auto-map | The **Prompts** block of the `mapping-suggest` workflow's entry, key `prompt`. The card links there. | The **Models** block of its catalog entry, key `model` | The role of the model that proposes a mapping from a trigger's event to a workflow's input. |
The copilot belongs to an agent and Auto-map to a workflow, so their catalog
entries already edit their prompt and model, beside the rest of the entry. The
card links there once instead of offering a second editor. If you wrote your
own `mapping-suggest` workflow, it reads that prompt only if its code does, and
that model only if it calls `stackbone.models.use('model')`.
The copilot card also holds the switch that shows or hides the copilot for the
whole workspace. It is off in a new workspace, and only an owner or an admin
can change it. [Turn it on](/docs/home/features/studio-copilot#turn-it-on)
covers it.
## Edit a prompt on its card
The Guardrail classifier, Eval judge and Persona simulator cards edit their
prompt in place.
1. **Read the text in force.** The badge says **Built-in default** while the
card runs on the text Stackbone ships, and **Edited · v3** (with the version
number) once your text runs.
2. **Click Edit.** The editor opens on the text in force. Saving publishes
your text, so there is no draft step on this screen.
3. **Reset to built-in** when you want the shipped text back. The button shows
only while your edit runs, and it asks you to confirm. Your versions stay in
the prompt's history.
The next call picks the change up within five seconds, with no restart and no
rebuild. If the box cannot read your published text, the caller runs on the
built-in text and logs why. A guardrail or an eval never fails because its
prompt could not be read.
## Edit a prompt on its catalog entry
The copilot's `instructions` and Auto-map's `prompt` show **Built-in default**
in their entry's **Prompts** block while nothing is published.
- **Edit** opens the editor on the built-in text. Saving publishes it.
- Once your text runs, click the key to open it. It works like any prompt:
**Edit** writes a new version, and you publish it from the history.
- **Reset to built-in** takes your text out of service after you confirm. The
versions stay in the history.
A copilot edit applies from your next message. A reply that is already
answering finishes on the text it started with. Auto-map reads its prompt on
every run. The [Studio copilot](/docs/home/features/studio-copilot#edit-its-instructions-and-model)
page covers the copilot's entry in full.
## What stays fixed
On the classifier, the judge, the simulator and Auto-map, you edit the
**guidance** only: the sentence or two that sets the model's role. After your
text, Stackbone always adds two things of its own:
- The answer format the caller reads back, such as the classifier's verdict or
the judge's verdict and score.
- The safety rules around the material under review: the delimiters that mark
where the checked text, the graded answer or the conversation starts and
ends, and the rule to never follow instructions found inside it.
So an edit can make a check stricter or a judge gentler. It cannot break how
the answer is read, and it cannot switch off the defence against prompt
injection in the material the model reads.
The copilot is the exception, because its prompt is its whole system prompt.
Its tools reach it separately, and the box, not the prompt, decides
[which writes ask you first](/docs/home/features/studio-copilot#some-writes-ask-you-first).
## Pick a model
The Guardrail classifier, Eval judge and Persona simulator cards each carry a
model picker. The Studio copilot and Auto-map cards name the model they run on
and link once to their catalog entry, where the **Prompts** and **Models**
blocks edit both.

_The two eval callers. The judge card points to the criterion that grades with a workflow of your own._
| Card | Workspace setting | With nothing picked |
| -------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------- |
| Studio copilot | None | The workspace **Default model**. With neither, the copilot does not answer, and its error names **Settings › Workspace**. |
| Guardrail classifier | `guardrailModel` | `openai/gpt-4o-mini` |
| Eval judge | `judgeModel` | `openai/gpt-4o-mini`. A rubric criterion that names its own model uses that one instead. |
| Persona simulator | `simulatorModel` | `openai/gpt-4o-mini`. A suite that names its own simulator model uses that one instead. |
| Auto-map | None | The workspace **Default model**. With neither, Auto-map fails, and its error names **Settings › Model defaults**. |
The picker's row for nothing picked names the fallback, for example
`Default · openai/gpt-4o-mini`. A pick saves at once: this screen has no
**Save** button. Once you pick a model, **Reset** beside the picker goes back
to the fallback. The
pickers list the chat models your [model provider](/docs/home/features/gateway)
advertises. The Persona simulator card warns when it and the Eval judge land
on the same model, because one model that plays the user and then grades the
answer partly agrees with itself.
The **Default model** lives on **Settings › Workspace**. Your code reads it and
the four keys above with
[`stackbone.settings`](/docs/sdk/platform/settings#the-keys-today).
## Judge with a workflow of your own
The Eval judge card frames the built-in judge. To grade answers with your own
rules instead, add the **Meets a rule of your own, judged by your workflow**
criterion to a suite on **Eval suites**, and pick one of your workflows to
grade with. [Evaluation](/docs/home/features/evaluation#build-a-suite)
lists every criterion.
## Read a run's trace
Auto-map reads its `prompt` key on every run. While nothing is published, the
trace shows that read as **Built-in default**, in the neutral colour, and not
as an empty prompt. A prompt your own code reads and finds empty still gets
the warning, so you can tell the two apart.
## Edit from the CLI
The three prompts the cards edit in place are ordinary prompts under the
owner kind `system`, so
[`stackbone prompts`](/docs/cli/reference/prompts#prompts-of-the-boxs-own-model-callers)
reads and writes them too:
```sh
stackbone prompts create prompt \
--owner-kind system --owner-name guardrail-classifier \
--name "Guardrail classifier" --file ./classifier-guidance.txt
```
`create` publishes version 1 at once. When the prompt already exists (you
edited it on the card before), `update` it and `publish` the new version.
`unpublish` returns the caller to its built-in text.
## Who can use it
Opening the screen, and every change on it, needs `config:write`, which the
`owner`, `admin` and `member` roles hold. A `viewer` or an `approver` who opens
it reads "Your role cannot open this". The cards carry prompt text, and a seat
that may not edit a prompt is not shown one.
## What's next
- [Studio copilot](/docs/home/features/studio-copilot#edit-its-instructions-and-model):
edit the copilot's instructions and model from its catalog entry.
- [Guardrails](/docs/home/features/guardrails#the-checking-model): the three
checks the classifier answers.
- [Evaluation](/docs/home/features/evaluation): suites, criteria and what the
judge and the simulator do during a run.
- [Gateway](/docs/home/features/gateway#pick-the-model-each-platform-tool-uses):
the Default model and the provider every one of these calls goes through.
- [`stackbone prompts`](/docs/cli/reference/prompts): the same prompts from a
terminal.