A support prompt cannot establish account entitlement from customer prose. Query an authorized service for tenant ID, seat limit, active seats, pending reservations, and record freshness, then reconcile the total. Verify the requester role separately from tenant membership. A member may ask for an explanation yet lack authority to withdraw another person's invite, buy seats, or change an account setting. Any such action needs the correct administrator or specialist path and a fresh permission check at execution time. Minimize account data in the customer draft; expose counts and next steps, not another employee's private details.
Support prompts: verify entitlement and requester authority
Operational case
N-47 has a limit of 47 seats: 46 active and one pending invite. That totals 47 reserved, leaving zero currently available. The requester is a verified member, not an admin, so the assistant can explain the allocation but cannot withdraw the pending invite or purchase capacity on the member's behalf. An authorized admin may review the pending reservation in the product. The assistant does not name the invited employee in the public reply, and it rechecks the ledger before any later change because the state may move while the ticket is open.
Tenant N-47: limit 47
Active 46 + pending 1 = reserved 47
Available now: 0
Requester role: member, not admin
Allowed draft: explain counts and admin path
Forbidden effect: withdraw invite or buy seats as memberPerformance and review cost
Checking S account records is O(S) with keyed lookups; one ticket usually needs a constant number of reads. The arithmetic is trivial but stale state can invalidate it, so attach a retrieval time or version. Permission checks must run where the side effect occurs, even if the prompt performed an earlier read. That redundancy prevents a convincing explanation from becoming unauthorized account administration.
Common Mistakes
- Do not infer an available seat from active count alone.
- Do not equate membership with admin permission.
- Do not expose the pending invitee's details to an unrelated requester.
Connected lessons
- Production prompt engineering
- Prompt Engineering
- Numeric prompts: let code calculate and the model explain
- Tool calls: validate intent and arguments before an external effect
- Support prompts: reconstruct ticket identity and chronology
- Support prompts: route by issue and verified urgency
- Support prompts: answer from current product guidance
- Support prompts: ask only the question that changes the next step
- Support prompts: separate reply, handoff, and resolution
- Project: handle Aster seat activation ticket T-47
- Customer-support case decisions
