What Enterprise Vibe Coding Means for Maximo & EAM Shops

🎯 Who this is for: Maximo developers, admins, practice leads and the managers who sign off on what touches production asset data.

Series: Part 12 of 13 — Enterprise Vibe Coding | Read time: 8 minutes

Picture a Maximo team at a water utility, the week after their MAS 9.2 upgrade. The admin spots a new pod in the OpenShift project, ending in -mcp. A developer has already pointed an AI agent at a dev environment and asked it to "find every automation script that still imports sun.misc". The answer comes back in a minute instead of an afternoon of grepping exported XML.

Then the practice lead asks the question that actually matters: "Great. Now who decides what it's allowed to change?"

That's where Maximo shops are in late 2026. The technology arrived faster than the operating model. This post is about the second part.

🔌 The Plumbing Arrived

For eleven posts we've talked about agents in banks, insurers and governments. Maximo has quietly caught up.

  • A native MCP server in MAS 9.2. It runs as its own pod (<instance>-mcp) on OpenShift. Its tools are generated from Manage OpenAPI specs — object structures, automation scripts, workflows, API routes and AI configurations. External agents connect through a route with an API key or JWT, and the same server powers Maximo Assistant.
  • Maximo skills for IBM Bob. IBM's Build Engineering team published maximo-code-optimization and maximo-java-conversion (Java business-object classes to automation scripts) in its public building-blocks repository, plus a demo repo that drives Maximo job-plan integration through MCP.
  • Mobile developers too. IBM's MAF Local Dev Mode extension supports the Bob IDE on MAS 9.1.21+ and 9.2.1+.
  • A headline number. IBM reports its own Maximo development team cut code-generation and refactoring tasks "that normally take days" to hours, with an "estimated 69% time savings". That's one sentence, IBM-reported, with no method published — Part 10 explains how to read numbers like that.

None of this is Bob-only. MCP is an open protocol, so Claude Code, GitHub Copilot, Cursor and Kiro can connect to the same Maximo endpoints. The agent you choose matters less than the rules you put around it.

🧭 Why Maximo Needs Its Own House Rules

IBM has done the platform work. The day-to-day practice is still up to each team: who holds the API keys, which environments an agent can touch, and who signs off before anything reaches production.

That matters because Maximo is not a generic codebase. It has object structures, launch points, security groups, site and org hierarchies, Jython 2.7 quirks and the Java 17 import changes that came with MAS 9. A generic agent doesn't know any of that out of the box, and a confidently wrong automation script on a work-order save event is very visible very quickly. Write those rules down before the first agent session, not after the first incident.

🛡️ The Boundary That Matters

If you remember one rule from this post: agents act through APIs, object structures and automation scripts — never through the database.

Why so firm? Because everything that makes Maximo trustworthy lives above the tables: security groups, field validation, status rules, workflow, audit and e-signature. An agent with a JDBC connection skips all of it. An agent using mxapiwodetail through the REST API gets checked by Maximo exactly like a human user would.

QuestionSafe patternRisky pattern
How does the agent reach Maximo?MCP server over REST/OSLC APIsDirect SQL / database credentials
Whose permissions does it use?Dedicated API key, least-privilege security groupA shared admin account
Where does it start?Read-only key on a dev or test environmentWrite access in production
How do changes ship?Automation scripts deployed through a reviewed pipelineAgent edits live scripts directly
Who approves writes?A named human, every timeAuto-approved "because it's just a status change"

The same least-privilege idea runs through IBM's own Bob design: in Bob V2, reads are auto-approved, while edits, commands, MCP calls and skills still need human approval. Copy that posture in your Maximo security groups and you're most of the way there.

⚠️ Be honest about the risk: In January 2026, researchers at PromptArmor showed a beta version of Bob's shell could be prompt-injected through a README into running malware when one command was auto-approved. IBM pledged fixes before GA. The lesson isn't "avoid Bob" — it applies to every agent. Any tool that reads untrusted text and can run commands needs approval gates and a narrow key. With Maximo, "narrow" means a security group that can read work orders, not one that can delete purchase orders.

🛠️ Where AI Actually Helps a Maximo Team

IBM's Neel Sundaresan put it bluntly at Think 2026: about 60% of work is migration, modernization and maintenance, and new code development is only about 15%. That describes most Maximo practices exactly — and it's good news, because that's where agents are strongest.

  • Customization archaeology. "Which scripts touch the WORKORDER save event?" "What does this 2014 Java class actually do?" Read-only questions with big time savings and almost no risk.
  • Java to automation scripts. Converting custom business-object classes to Jython is repetitive, pattern-driven work. Good fit for skills and written conversion guides — with a human testing every launch point.
  • MAS 9 upgrade clean-up. Finding removed imports (sun.misc.*, javax.xml.bind.*) and flagging them for Java 17 replacements.
  • Backlog and data questions. Overdue work orders, PM compliance and downtime trends, pulled through APIs and summarized for a planner.
  • Integration scaffolding. First drafts of publish channels, enterprise services and Postman tests.

One honest caveat from the community: a Maximo consultant testing Bob on BIRT reports, application XML and Java-to-Jython conversion found output quality depended almost entirely on the context supplied — business rules, naming, existing scripts. In other words: Part 11. House rules aren't optional in Maximo land.

🧰 The Toolbox: IBM + Community

Here's how the pieces fit, and where our own work sits alongside IBM's.

  • IBM's 9.2 MCP server — the native option, generated from your own instance's OpenAPI specs. If you're on 9.2, start here.
  • [Max_mcp](https://github.com/themaximoguys/Max_mcp) — TheMaximoGuys' Maximo MCP server: 175 purpose-built tools across 20 modules (work orders, assets, inventory, PMs, job plans, analytics, scheduling, autoscripts and more), with rate limiting, caching, retries and multi-environment config. Built for MAS 9.x and available on npm as @themaximoguys/maximo-mcp (proprietary license). It complements IBM's server with task-shaped tools like backlog and PM-compliance analysis.
  • [Max_Interfaces](https://github.com/themaximoguys/Max_Interfaces) — open source (MIT): 2,439+ Maximo API endpoints across 14 modules as Postman and OpenAPI collections, covering Maximo 7.x, 8.x and MAS 9, plus an automation-script deployment pipeline. It's the map of what your agent is allowed to call.
  • [Max_autoscripts](https://github.com/themaximoguys/Max_autoscripts) — open source (MIT): 67 sample Jython scripts, 28 templates, a coding standard, Java-to-Jython and TRM-to-Jython conversion guides and an AGENTS.md. House rules your agent can read on day one.

All of it is agent-neutral: plug it into Claude, Bob, Copilot, Cursor — any MCP-capable agent.

Key Takeaways

  • The plumbing is solved: MAS 9.2's native MCP server, IBM's Maximo Bob skills and MAF Local Dev Mode make Maximo agent-ready.
  • The practice is on you: day-to-day Maximo/EAM governance — keys, environments, approvals — is each team's job to write down.
  • Agents go through APIs and object structures, never the database — so Maximo security, validation and audit still apply.
  • Start read-only, in dev, with a dedicated key; every write gets a named human approver.
  • Maintenance and modernization are the sweet spot, and IBM's 69% figure for its own Maximo team is a promising, unverified claim — measure your own.

References

🧰 From TheMaximoGuys toolbox: Start with Max_Interfaces (open source, MIT) to map the APIs, then connect Max_mcp (on npm) with a read-only key. Part 13 walks through it step by step.

Series Navigation

Previous:Part 11 — Teaching the AI Your House Rules
Next:Part 13 — Your First Maximo AI Agent in an Afternoon
Series Index:Enterprise Vibe Coding