Rocket EVA is moving from conversational mainframe assistance toward governed agent execution. Rocket Software disclosed an expanded platform on 23 September and introduced PlanGuard, a layer that evaluates an agent’s proposed action before it reaches a mission-critical system. The useful distinction is architectural: the policy decision happens at invocation time, when the user, request, tool and operating context are known, rather than relying only on permissions granted long before the task began.

Key takeaways

  • PlanGuard sits between AI reasoning and system execution.
  • Rocket says actions can remain scoped, logged and subject to human oversight.
  • The platform is being piloted across five mainframe-heavy sectors.

How Rocket EVA changes the control path

Rocket’s announcement describes EVA as a model-agnostic agent platform that correlates operational evidence across mainframe systems. It targets work such as diagnosing job failures, investigating CICS queues, monitoring batch-service levels and finding configuration or performance problems. PlanGuard is intended to put a policy and identity checkpoint before the platform can execute an approved action.

SiliconANGLE’s independent report adds that the proposed action can be permitted, denied or routed for another approval. It also reports that a temporary execution identity can be limited to the approved task and revoked afterward. Those are important design claims, but buyers still need to validate them in their own security managers, logs and approval workflows.

PlanGuard execution pathA request moves through reasoning, policy evaluation and approval before a scoped identity reaches the mainframe.RequestReasonPolicy checkand approvalScoped identityExecute

Why mainframe agents need a different permission model

Mainframes often run high-value systems with mature access controls. An AI agent does not remove those controls, but it can create more frequent and more contextual requests. A standing account with broad privileges would turn an assistant into a new concentration of risk. Task-scoped identity and an explicit policy decision reduce that exposure only if the underlying enforcement system remains authoritative and the temporary access is reliably revoked.

Auditability is equally important. Operators need a chain that ties a person to the request, the agent’s proposed step, the policy result, the execution identity and the outcome. The record must survive model changes and be readable by security teams who did not build the agent. Rocket says activity is logged; customers should test completeness, tamper resistance and export before allowing production changes.

The product test is governed execution in practice

Early value may come from investigation rather than autonomous change. Correlating logs, job output and operational context can shorten diagnosis while leaving remediation with a human. Production authority should expand only after teams measure false conclusions, permission denials, approval latency and rollback quality. Our coverage of LittleHorse agent guardrails and AWS AgentCore Runtime V2 shows the same market pressure: agent platforms are being judged on execution controls, not conversational polish.

Rocket EVA’s mainframe proposition is not that an AI agent should bypass established controls; it is that each proposed action should be evaluated in context, executed with narrow authority and leave evidence that an operator can audit.

Facts at a glance

Fact Detail
Announcement 23 September 2026
Platform Rocket EVA for mission-critical systems
New layer Rocket PlanGuard
Control point Between AI reasoning and system execution
Pilot sectors Finance, government, insurance, retail and telecom

Frequently asked questions

What is Rocket EVA?

An agentic AI platform for investigating and automating operational work on mainframe and other mission-critical systems.

What does PlanGuard do?

It evaluates proposed actions against policy and identity context before execution and records activity for audit.

Is Rocket EVA fully autonomous?

The announcement emphasizes governed actions and human oversight where required; deployment scope remains an organisational decision.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.