Mainframe teams are under pressure to resolve complex operational issues faster, extend scarce expertise, and safely introduce AI-driven automation. Rocket® EVA™ 2.0 advances that vision by bringing governed AI agents to mission-critical mainframe and hybrid IT operations.
The impact is already visible. During a pilot with a large financial institution, EVA investigated a complex performance incident that spanned multiple interconnected mainframe environments, including MQ, CICS, workload management, and infrastructure services. Using historical SMF data, EVA analyzed millions of operational records across multiple systems, correlated events into a coherent timeline, and helped identify the probable chain of cause and effect behind the outage. What had previously required extensive manual analysis across multiple teams became a much faster, evidence-based investigation.
Rocket EVA has been named a 2026 Tech Ascension Award winner in the AI-Powered Enterprise Agent Solution of the Year category. The recognition places EVA among a strong field of 2026 AI award recipients that includes solutions from Lenovo, Zoom, Ford, and other technology leaders across the program.
We look forward to continuing to bring value to organizations looking to apply governed agentic AI across mainframe and hybrid IT operations. View the 2026 AI Award winners
The expansion of Rocket EVA has also drawn industry attention for its approach to governed agentic AI on the mainframe. Recent coverage highlights how EVA combines operational reasoning, policy-based controls, identity management, and auditability to help organizations apply AI across mission-critical environments while maintaining enterprise oversight.
Read SD Times coverage of governed agentic AI on the mainframe, VMblog coverage of Rocket EVA and PlanGuard, and Paul Gillin's SiliconANGLE coverage of Rocket EVA 2.0 for additional perspectives on the announcement.
EVA takes a natural-language request and, once a user initiates it, independently runs a multistep investigation across connected tools, data sources, logs, dashboards, and operational context. It correlates evidence, evaluates likely causes, and returns findings, a recommendation, and the supporting proof behind it.
EVA is currently focused on analysis. It does not make unsupervised changes to production systems. Phil Buckellew, president of Rocket Software's Infrastructure Modernization Business Unit, explains: “Today, EVA can independently orchestrate complex investigations once a user initiates a request. Rather than requiring operators to manually navigate multiple consoles, dashboards, logs and reports, EVA brings those sources together and provides a unified, context-rich explanation of what is happening in the environment and why.”
This is especially valuable when multiple specialists would normally hold different pieces of the picture, including operational diagnostics, incident investigation, workload analysis, and root-cause identification. EVA brings that evidence together without requiring every operator to be a deep z/OS expert.
While EVA today focuses on independently orchestrating investigations, PlanGuard establishes the governance foundation needed as organizations expand agent use cases toward approved system actions.
Introducing PlanGuard: The two-stage governance layer for agentic AI
EVA 2.0 introduces Rocket® PlanGuard™, a two-stage governance layer designed for agentic AI in mission-critical environments.
Before any tool is invoked or action executed, PlanGuard evaluates the caller’s attributes, request, session context, tool selection, environmental conditions, and organizational policies. It then determines whether the action should be permitted, denied, or escalated for human approval. Nothing runs until that check is complete.
Buckellew explains: “This invocation-time approach is important for agentic AI because decisions can no longer rely solely on permissions granted during account provisioning. Instead, PlanGuard evaluates the specific user, request, tool and operational context involved in each action before execution is allowed.”
When PlanGuard approves an action, it creates a temporary, task-specific execution credential scoped only to that approved operation. The credential exists only for the duration of the task and is revoked when no longer needed, limiting the window of exposure for any single agent action.
PlanGuard builds on existing enterprise security managers such as RACF, ACF2, and Top Secret rather than replacing them. Those systems remain the foundation of mainframe security. PlanGuard adds the governance layer agentic AI requires and provisions identities that operate within the existing authorization framework.
Auditability is built into EVA’s architecture. Every governed action is recorded with who initiated the request, what the agent proposed, which policy was evaluated, whether approval was required, what identity was used, and what action was ultimately taken. The record is tamper-evident and hash-chained.
As Buckellew puts it: “This creates a complete chain of evidence that allows operators, security teams and auditors to understand not only what occurred, but why it occurred, with which identity, and under which policy decision.” For organizations in financial services, insurance, and other regulated industries, that chain of evidence can support compliance requirements.
A major retailer faced a production CICS region that had halted after exhausting temporary storage. The team knew what had happened, but not why. EVA analyzed the incident data and determined that the issue was not general system contention. It was a localized, application-driven problem. EVA isolated the primary source, identified contributing systems, and connected the incident to a specific workload pattern and likely application owner. That narrowed a broad infrastructure question to a specific application domain and gave the team a clear starting point for remediation and prevention.
In other cases, investigations that had remained open for two months were narrowed to a likely root cause in minutes. EVA is not replacing expert judgment. It is accelerating data gathering and correlation so experts can focus on validation and resolution.
EVA combines institutional knowledge encoded through operational processes, governance policies, tool integrations, investigative workflows, and accessible systems with live operational data and current system context.
Because EVA reasons against live data rather than relying only on a static knowledge base, its recommendations can evolve as configurations change, workloads shift, applications are deployed, and operational policies are updated. This helps organizations extend deep expertise beyond a small group of tenured specialists while keeping guidance grounded in the current environment.
Pricing is consumption-based and tied to anticipated users and usage volume. Customers choose their own LLM provider and keep those costs visible and under their control. EVA is designed to use only the information required for an investigation rather than sustaining long, open-ended conversational exchanges, helping manage LLM consumption while still delivering detailed analysis.
Rocket’s internal analysis estimates roughly 3.2x annual ROI, including LLM costs. The estimate reflects escalation deflection, faster resolution of P1 and P2 incidents through accelerated diagnostics and root-cause analysis, and around-the-clock access to operational expertise. This is an internal projection, not an independently audited result, and should be treated as a planning input rather than a performance guarantee. Specific pricing is available through Rocket Software sales representatives.
PlanGuard provides the policy and identity controls governed agentic AI requires, but each organization must still determine which actions agents may take autonomously, when human approval is required, and how results should be validated before reaching production. Those decisions should reflect the organization’s risk tolerance, regulatory obligations, and operational discipline.
To explore how EVA could support a representative operational scenario in your own mainframe environment, contact your Rocket Software representative or visit the Rocket EVA product page.
Rocket® EVA™
Rocket EVA™ es una interfaz conversacional impulsada por IA que proporciona diagnósticos operativos precisos e integrales en todos los sistemas principales.
¿No tienes un experto en CICS para actividades Rocket EVA? No hay problema.
IDC Link analiza cómo Rocket EVA™ lleva la IA agencial a las operaciones de mainframe.
