System prompts and models

Stackbone makes model calls of its own inside your box (the container running your workspace, or stackbone dev on your laptop). The Studio copilot answers you, a guardrail asks a model about a turn, an eval grades an answer. Settings › Model defaults in Studio gives each of these callers one card, with the text it frames its model with and the model it runs on. Every card starts on what Stackbone ships, and a reset goes back to it.

The first two cards. The copilot card links to its catalog entry. The classifier card edits its prompt in place.

The five callers

Caller Where you edit its prompt Where you pick its model What the prompt controls
Studio copilot The Prompts block of its catalog entry, key instructions. The card links there. The Models block of its catalog entry Its whole system prompt: how it talks and works. Its tools, and the screen you have open, reach it separately.
Guardrail classifier Its card Its card How the model is framed when a guardrail asks it about a turn (prompt injection, harmful content, off-limits subjects).
Eval judge Its card Its card The stance of the model that grades an answer against a rubric criterion.
Persona simulator Its card Its card How the model is framed when it plays the user in an eval case that asks a question back.
Auto-map The Prompts block of the mapping-suggest workflow's entry, key prompt. The card links there. The Models block of its catalog entry, key model The role of the model that proposes a mapping from a trigger's event to a workflow's input.

The copilot belongs to an agent and Auto-map to a workflow, so their catalog entries already edit their prompt and model, beside the rest of the entry. The card links there once instead of offering a second editor. If you wrote your own mapping-suggest workflow, it reads that prompt only if its code does, and that model only if it calls stackbone.models.use('model').

The copilot card also holds the switch that shows or hides the copilot for the whole workspace. It is off in a new workspace, and only an owner or an admin can change it. Turn it on covers it.

Edit a prompt on its card

The Guardrail classifier, Eval judge and Persona simulator cards edit their prompt in place.

  1. Read the text in force. The badge says Built-in default while the card runs on the text Stackbone ships, and Edited · v3 (with the version number) once your text runs.

  2. Click Edit. The editor opens on the text in force. Saving publishes your text, so there is no draft step on this screen.

  3. Reset to built-in when you want the shipped text back. The button shows only while your edit runs, and it asks you to confirm. Your versions stay in the prompt's history.

The next call picks the change up within five seconds, with no restart and no rebuild. If the box cannot read your published text, the caller runs on the built-in text and logs why. A guardrail or an eval never fails because its prompt could not be read.

Edit a prompt on its catalog entry

The copilot's instructions and Auto-map's prompt show Built-in default in their entry's Prompts block while nothing is published.

  • Edit opens the editor on the built-in text. Saving publishes it.
  • Once your text runs, click the key to open it. It works like any prompt: Edit writes a new version, and you publish it from the history.
  • Reset to built-in takes your text out of service after you confirm. The versions stay in the history.

A copilot edit applies from your next message. A reply that is already answering finishes on the text it started with. Auto-map reads its prompt on every run. The Studio copilot page covers the copilot's entry in full.

What stays fixed

On the classifier, the judge, the simulator and Auto-map, you edit the guidance only: the sentence or two that sets the model's role. After your text, Stackbone always adds two things of its own:

  • The answer format the caller reads back, such as the classifier's verdict or the judge's verdict and score.
  • The safety rules around the material under review: the delimiters that mark where the checked text, the graded answer or the conversation starts and ends, and the rule to never follow instructions found inside it.

So an edit can make a check stricter or a judge gentler. It cannot break how the answer is read, and it cannot switch off the defence against prompt injection in the material the model reads.

The copilot is the exception, because its prompt is its whole system prompt. Its tools reach it separately, and the box, not the prompt, decides which writes ask you first.

Pick a model

The Guardrail classifier, Eval judge and Persona simulator cards each carry a model picker. The Studio copilot and Auto-map cards name the model they run on and link once to their catalog entry, where the Prompts and Models blocks edit both.

The two eval callers. The judge card points to the criterion that grades with a workflow of your own.

Card Workspace setting With nothing picked
Studio copilot None The workspace Default model. With neither, the copilot does not answer, and its error names Settings › Workspace.
Guardrail classifier guardrailModel openai/gpt-4o-mini
Eval judge judgeModel openai/gpt-4o-mini. A rubric criterion that names its own model uses that one instead.
Persona simulator simulatorModel openai/gpt-4o-mini. A suite that names its own simulator model uses that one instead.
Auto-map None The workspace Default model. With neither, Auto-map fails, and its error names Settings › Model defaults.

The picker's row for nothing picked names the fallback, for example Default · openai/gpt-4o-mini. A pick saves at once: this screen has no Save button. Once you pick a model, Reset beside the picker goes back to the fallback. The pickers list the chat models your model provider advertises. The Persona simulator card warns when it and the Eval judge land on the same model, because one model that plays the user and then grades the answer partly agrees with itself.

The Default model lives on Settings › Workspace. Your code reads it and the four keys above with stackbone.settings.

Judge with a workflow of your own

The Eval judge card frames the built-in judge. To grade answers with your own rules instead, add the Meets a rule of your own, judged by your workflow criterion to a suite on Eval suites, and pick one of your workflows to grade with. Evaluation lists every criterion.

Read a run's trace

Auto-map reads its prompt key on every run. While nothing is published, the trace shows that read as Built-in default, in the neutral colour, and not as an empty prompt. A prompt your own code reads and finds empty still gets the warning, so you can tell the two apart.

Edit from the CLI

The three prompts the cards edit in place are ordinary prompts under the owner kind system, so stackbone prompts reads and writes them too:

stackbone prompts create prompt \
  --owner-kind system --owner-name guardrail-classifier \
  --name "Guardrail classifier" --file ./classifier-guidance.txt

create publishes version 1 at once. When the prompt already exists (you edited it on the card before), update it and publish the new version. unpublish returns the caller to its built-in text.

Who can use it

Opening the screen, and every change on it, needs config:write, which the owner, admin and member roles hold. A viewer or an approver who opens it reads "Your role cannot open this". The cards carry prompt text, and a seat that may not edit a prompt is not shown one.

What's next

  • Studio copilot: edit the copilot's instructions and model from its catalog entry.
  • Guardrails: the three checks the classifier answers.
  • Evaluation: suites, criteria and what the judge and the simulator do during a run.
  • Gateway: the Default model and the provider every one of these calls goes through.
  • stackbone prompts: the same prompts from a terminal.
BUILT WITH ❤️ FROM CANADA AND SPAIN