Constrained Automata: A Formal Tool for Risk Assessment and Mitigation