Lesson 21 / 25
Data Minimisation in Context
Only send what the task needs.
Less data, less risk
Everything you put in context may be logged, cached or echoed in the answer. Apply data minimisation: send only the fields the task needs, mask or remove personal data and secrets, enforce the user's access rights at retrieval time (never retrieve documents the user is not allowed to see and then hope the model will not reveal them), and know where your provider stores prompts and for how long. Minimising context also usually improves quality by removing distractors.
Retrieval with access control (sketch)
Filter before the model sees anything. Not run here.
def retrieve_for(user, query, k=6):
hits = index.search(query, k=50)
allowed = [h for h in hits if user.can_read(h.doc_id)] # enforce ACLs first
return [redact_pii(h) for h in allowed[:k]] # then minimise fieldsNever rely on the model to hide data
If the user must not see it, it must not be in the context.
Quick check: Where should document access rights be enforced?
- In an instruction asking the model not to reveal it
- At retrieval time, before content reaches the model
- After the answer is shown
- Nowhere, the model decides
Answer
At retrieval time, before content reaches the model — Context should only contain what the user may see.