Rocket Software adds governed AI agents to mainframe ops
EVA 2.0 introduces PlanGuard security layer to evaluate and control agent actions before execution while preserving existing mainframe access controls.
Rocket Software is bringing agentic AI to mainframe operations with a security-first approach that stops short of giving agents unrestricted access to critical systems.
The company's Enterprise Virtual Assistant platform, now approaching version 2.0, introduces PlanGuard—a security layer that evaluates every proposed agent action before execution. The addition addresses a core tension in enterprise AI: organizations want to apply generative AI to mainframe work but cannot afford to compromise decades-old identity controls, policy frameworks, and compliance requirements.
How PlanGuard mediates agent actions
PlanGuard functions as a policy decision point that examines multiple factors when an agent proposes an action: the caller's identity, the specific request, the session context, the tool being invoked, environmental conditions, and organizational rules. Based on that evaluation, it can permit the action, deny it, or require human approval.
When permission is granted, PlanGuard creates a temporary execution identity scoped strictly to the approved task, then revokes it when the work completes. This invocation-time authorization model differs from traditional account provisioning, where permissions are granted upfront and persist.
"This invocation-time approach is important for agentic AI because decisions can no longer rely solely on permissions granted during account provisioning," said Phil Buckellew, president of Rocket's Infrastructure Modernization Business Unit, according to SiliconANGLE. "Instead, PlanGuard evaluates the specific user, request, tool and operational context involved in each action before execution is allowed."
The system works alongside established mainframe security managers including RACF, ACF2, and Top Secret rather than replacing them. It also generates a tamper-evident, hash-chained audit trail that records who initiated each request, what the agent proposed, which policy applied, whether approval was required, and what action resulted.
Investigation before automation
EVA's current emphasis is on multistep investigations triggered by natural-language requests. The platform selects connected tools and data sources, collects operational context, correlates evidence across systems, and returns findings with supporting evidence—work that traditionally requires specialists to search separate logs, reports, and consoles.
Rocket cited pilot results from a large South American financial institution where an operations team spent roughly three weeks investigating a production problem. After receiving System Management Facilities records and operational context, EVA identified a probable root cause with supporting evidence in less than a day.
In another pilot, a major retailer knew a production CICS region had stopped after exhausting temporary storage but didn't know why. EVA determined the event was a localized, application-driven issue rather than general system contention, isolated the main source of activity, and connected the failure to a workload pattern and likely application owner.
Why it matters
Mainframe systems run core operations at banks, insurers, retailers, and government agencies—environments where AI mistakes carry regulatory and operational consequences. PlanGuard's architecture reflects a pragmatic path: enable AI agents to accelerate investigation and analysis while keeping humans in the loop for execution decisions. The broader test will be whether customers eventually trust governed agents to take action autonomously, and whether PlanGuard's controls prove sufficient for auditors and regulators.
Rocket is testing EVA with organizations in financial services, government, insurance, retail, and telecommunications. The platform uses consumption-based pricing tied to expected users and volume, with customers retaining control over their choice of large language model providers and associated costs. Rocket estimates a typical deployment can generate 3.2 times annual return on investment through fewer specialist escalations and faster incident resolution, though that projection is the company's own analysis rather than an independently verified result.
Details were first reported by SiliconANGLE.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call