Several independent layers of protection, so one failing does not expose everything.
You have done this if
You had a WAF at the edge, auth at the gateway, permission filters in retrieval and output checks before the answer.
Say it in a review
Prompt injection is handled in layers: input isolation, scoped tools, approval for actions and output checks.
On the AI Application map Edge, API Gateway, Retrieval