**Design mitigations:** Changes to how the system is built — different training data, different features, different output format, different decision thresholds - **Deployment mitigations:** Changes to how the system is used — restricted scope, mandatory human review, minimum confidence thresholds f