"How to prompt the model not to leak sensitive data" is not the right discussion to be having. It's a probability model, which means that
every conceivable behavior is available in the confines of its code. There is
no way to prevent an LLM with access to private information from divulging that information, or from attempting to sabotage systems it has access to. The
only solution is to lock every LLM query in the entire stack behind the same deterministic role-based access controls that determine resources available to the current user.
I wish I could say I'm shocked a tech company architected internal systems with a built-in backend RBAC bypass like this, but with the degree to which they've marketed LLM-based solutions (on a subscription model that benefits them directly) as a wholesale replacement for deterministic code, it's no surprise they've become addicted to their own drug.