
Governed AI for Mainframes: EVA 2.0 with PlanGuard narrows risk as enterprises experiment with agentic automation
Published by AINave Editorial • Reviewed by Ramit
Rocket Software's EVA 2.0 adds PlanGuard, a runtime policy checkpoint that evaluates every action an AI agent proposes on mainframe systems before execution. For builders managing governed AI agents for mainframe operations, this means you can now let agents investigate and eventually automate tasks without giving them unfettered access to critical resources. The platform works alongside existing security managers like RACF, ACF2, and Top Secret, and pilot results show investigation times dropping from weeks to days.
PlanGuard: A Runtime Policy Checkpoint for Mainframe Agents
PlanGuard is the headline feature in EVA 2.0. It operates as a policy decision point that examines the caller, request, session, selected tool, environmental conditions, and organizational rules when an agent proposes an action. It can permit, deny, or require additional approval. If permitted, it creates a temporary execution identity limited to that specific task and revokes it when the work completes. Phil Buckellew, president of Rocket's Infrastructure Modernization Business Unit, described this as an "invocation-time approach" because agentic decisions cannot rely solely on permissions granted during account provisioning (SiliconANGLE).
How PlanGuard Fits With Existing Mainframe Security
Critically, PlanGuard does not replace RACF, ACF2, or Top Secret. Instead, it adds a contextual authorization layer on top. Customers keep their existing mainframe controls as the enforcement framework while allowing the agent to operate with short-lived, policy-limited identities. Rocket says the system also records who initiated a request, what the agent proposed, which policy was applied, whether approval was needed, the identity used, and the resulting action. EVA includes a tamper-evident, hash-chained audit trail to make the entire decision chain traceable (SiliconANGLE, Rocket Software announcement).
Real-World Pilots: Faster Root Cause Analysis
Rocket is testing EVA with organizations in financial services, government, insurance, retail, and telecom. In one pilot, a South American financial institution spent about three weeks investigating a production problem. After feeding the relevant System Management Facilities records to EVA, the agent identified a probable root cause and supporting evidence in less than a day. In another case, a major retailer knew a production CICS region had stopped after exhausting temporary storage but didn't know why. EVA determined the event was a localized application-driven issue, not general system contention, and isolated the contributing systems and probable application owner (SiliconANGLE).
Pricing, ROI, and the Open Question of Autonomous Execution
EVA uses a consumption-based pricing model tied to expected users and usage volume. Customers can use their preferred LLM provider and control those costs. Rocket projects a 3.2x annual return on investment including AI costs, based on fewer specialist escalations and faster incident resolution. That figure is Rocket's analysis, not an independent audit (SiliconANGLE). The real test will be whether customers move from AI-assisted investigation to governed execution. PlanGuard provides the policy and identity controls, but organizations still need to decide which actions agents may take autonomously, when humans must approve, and how to validate conclusions before changes hit production.
FAQs
Sources
- Rocket Software brings governed AI agents to mainframe operations - SiliconANGLE
- BMC Brings Governed AI Agents to Enterprise... - BMC Software
- SiliconANGLE theCUBE - YouTube
- CloudFrame: Mainframe Application Modernization with Judicious Use...
- NEAR: The Currency of Agents
- Rocket Software Advances Governed, Agentic AI on the Mainframe
- Rocket Software Advances Governed, Agentic AI on the Mainframe with Rocket® EVA™
- Rocket Software Advances Governed, Agentic AI on the ...
- Rocket Software Advances Governed, Agentic AI on the ...
- Rocket Software Advances Governed, Agentic AI on the ...
- Rocket Software Advances Governed, Agentic AI on the Mainframe with Rocket® EVA™
- Rocket's mainframe agent must clear a policy check before every...
- Harness Engineering for Reliable, Governed AI Agents - YouTube
- Alteryx adds governed AI tools to analytics platform






















