Rocket Software Inc. is expanding its Enterprise Virtual Assistant agentic artificial intelligence platform to help enterprises investigate and eventually automate operational work on mainframe systems while stopping short of giving AI agents unrestricted access to critical resources.
The company said today that the forthcoming EVA 2.0 will add PlanGuard, a security layer that evaluates an agent’s proposed action before execution. The platform targets organizations that want to apply generative AI to mainframe operations while retaining existing identity controls, policy enforcement and audit trails.
EVA can already conduct multistep investigations after a person submits a natural-language request. It selects connected tools and data sources, collects operational context, correlates evidence across systems and returns findings, recommendations and supporting evidence. The current emphasis is analysis rather than unsupervised system changes.
“Today, EVA can independently orchestrate complex investigations once a user initiates a request,” said Phil Buckellew, president of Rocket’s Infrastructure Modernization Business Unit. “Rather than requiring operators to manually navigate multiple consoles, dashboards, logs and reports, EVA brings those sources together and provides a unified, context-rich explanation of what is happening in the environment and why.”
Careful provisioning
PlanGuard is designed to mediate that transition. It operates first as a policy decision point, examining the caller, request, session, selected tool, environmental conditions and organizational rules when an action is proposed. It can permit or deny the action or require another approval. If it grants permission, it creates a temporary execution identity limited to the approved task and revokes it when the work is complete.
“This invocation-time approach is important for agentic AI because decisions can no longer rely solely on permissions granted during account provisioning,” Buckellew said. “Instead, PlanGuard evaluates the specific user, request, tool and operational context involved in each action before execution is allowed.”
Rocket said PlanGuard works with established mainframe security managers including RACF, ACF2 and Top Secret rather than replacing them. Customers can apply contextual and short-lived authorization while keeping their existing mainframe controls as the underlying enforcement framework.
The system also records who initiated a request, what an agent proposed, which policy was applied, whether approval was necessary, the identity used for execution and the resulting action. EVA adds a tamper-evident, hash-chained audit trail intended to make the agent’s reasoning and activity traceable to identifiable people.
Buckellew said the records are designed to support operational and regulatory review: “This creates a complete chain of evidence that allows operators, security teams and auditors to understand not only what occurred, but why it occurred, with which identity, and under which policy decision,” he said.
Time saved
Rocket is testing EVA with organizations in financial services, government, insurance, retail and telecommunications. It said pilot results show that the enhancement shortens investigations that traditionally require several specialists to search separate logs, reports and consoles.
Buckellew said an operations team at a large South American financial institution spent about three weeks investigating a production problem. After receiving the relevant System Management Facilities records and operational context, EVA identified a probable root cause and supporting evidence in less than a day.
In another pilot, a major retailer knew that a production CICS region had stopped after exhausting temporary storage resources but didn’t know the cause. EVA concluded that the event was a localized, application-driven issue rather than general system contention. It isolated the main source of activity, identified contributing systems and connected the failure to a workload pattern and likely application owner.
Buckellew said EVA’s role goes beyond displaying system data: “EVA is not simply surfacing metrics or dashboards,” he said. “It is correlating operational evidence, identifying likely causes, explaining its reasoning and helping teams move from knowing what happened to understanding why it happened.”
The platform combines live operational information with institutional knowledge embedded in workflows, policies, tool integrations and connected systems. Rocket said that this can extend scarce mainframe expertise to less-experienced employees while keeping recommendations aligned with changing applications and configurations.
EVA uses a consumption-based pricing model tied to expected users and usage volume. Customers can use their preferred large language model providers and retain control over those model costs. Rocket estimates that a typical deployment can generate a 3.2-times annual return on investment, including LLM expenses, through fewer specialist escalations, faster resolution of high-priority incidents and round-the-clock access to operational knowledge. That projection is Rocket’s analysis, not an independently verified result.
The broader test will be whether customers move beyond AI-assisted investigation to governed execution. PlanGuard supplies policy and identity controls, but organizations must still decide which actions agents may take, when people must approve them and how to validate conclusions before changes reach production.




