Jean-Denis Greze on why Town's agent can't send email
Town co-founder Jean-Denis Greze talks to Michael Grinich at AI Engineer World's Fair 2026 about draft-only agents, earning trust, and shared data silos.
Town's assistant reads your email, learns how you work, and writes your replies. What it cannot do is press send. Out of the box, none of Town's automations take external write actions: the AI is not allowed to send an email, only to leave a draft in your outbox. Co-founder Jean-Denis Greze treats privacy, security, and not making the user look stupid as non-negotiable. Michael Grinich sat down with Greze, who worked at Dropbox and spent years as CTO of Plaid before starting Town, at the AI Engineer World's Fair 2026 in San Francisco.
The idea came out of a failed pivot
Greze founded the company in late 2024 with Tony Vincent, previously director of applied AI at Google. Its first product was AI for tax preparers. The team got far into the problem of preparing a return with agents and never solved the go-to-market, so they started looking at a pivot. The signal was sitting in the work around the work: the tax preparers whose job they were automating still burned enormous time setting up calls with customers, answering near-identical questions from each one, and reconstructing before a meeting what a customer had wanted to discuss two weeks earlier.
They built the Town prototype in two weeks and had roughly 20 daily active users within days of putting it online. Greze treats that as the real signal. The first 10 DAUs of a self-serve product are the hardest ones to get, since they have to be people who aren't your friends or family. The team gave itself a month to figure out the product and has grown organically since. At the time of the interview, Town had been launched for a month, and the current version of the company was six months old.
The failure mode is embarrassment
Most agent post-mortems are about accuracy. Greze's are about dignity. You can never send an email that makes the user look stupid, he told Grinich, or the user is finished with the product.
That asymmetry is the whole design constraint. "Trust, you can earn trust over years and lose it in a minute". Products that try to chew on too much from the start hit it on day three: schedule a meeting at the wrong time, overlapping something else, or without accounting for time zones, and the user is gone. Once someone decides a product is bad, they have to hear about it dozens of times before they'll try again.
So Town starts small on purpose. The opening automations aren't ambitious, they save a few minutes a day, and the jobs get bigger over the first couple of months as the product earns the right to do them.
Draft-only is a blast radius decision
The draft-in-your-outbox default is what makes a bad output survivable. If Town writes a dumb email, you edit two sentences or you delete it. You're mildly annoyed, but nothing left the building and nobody saw it. No data was exfiltrated and you weren't made to look stupid, so the trust account isn't debited.
Greze is explicit that this costs capability and that he'll pay it. Town is "willing to be a little less powerful, but at same time more simple, and like smaller blast radius". As the models improve and the product improves, he expects to get somewhat more aggressive, but only along paths that don't spend the trust users have already extended.
How an automation earns a promotion
The ladder out of draft-only is where the design gets specific. Town treats permission escalation as something an automation has to qualify for.
After Town has asked for your approval on the same kind of action about ten times, forwarding a certain class of email to your billing department, say, it asks whether it should stop asking. You click to grant it. The click is load-bearing: "you don't want the AI to be able to change its own permissions".
The negative case matters more than the positive one. If, across those ten attempts, you edited half the drafts or didn't send them, Town reads that as trust not earned and never offers to automate the workflow. Approval history becomes the eval set. An agent that keeps needing corrections doesn't get promoted, and no human has to notice it happening.
Building for people who will never read your docs
Greze spent years at Plaid selling to developers who read API docs for fun. Town's customers are everyday people who don't have time to work out how routines, skills, or integrations fit together, which rules out most of the standard agent-builder playbook.
His answer is to solve horizontal problems rather than get close to every vertical. Four of them cover most knowledge work: replying to common emails, scheduling meetings, preparing for meetings, and never dropping a to-do item. Email replies generalize better than they look. For a recruiter or a salesperson, most responses collapse into roughly 10 to 15 templates, and a system that infers those templates from your inbox and outbox serves both roles. On top of that base the platform verticalizes over time, so a nurse, a plumber, a business owner, and a white-collar worker end up with different recommendations.
That the horizontal bet works at all is easier to believe with a concrete inbox in mind. Town has a sizable community of Australian plumbers, one of whom told the company he gets 300 emails a day spanning emergencies, active job sites, potential new clients, and supplier bills. Sorting that is a triage problem before it is a domain problem.
The research loop lives inside the product. There's a small bug button everywhere in the experience, and those reports feed fixes to workflow trajectories. Town can't look at your session and asks permission before reviewing trajectories even at a high level. When someone asks Town to plan a trip, something it hasn't built, the AI says it can't, then asks whether it may capture the feedback; the user clicks yes and the roadmap gets a data point. Greze's framing is that AI lets you skew the experience toward feedback at the exact moment of failure, which puts a first pass of PM and customer success work inside the product itself.
The emotional hook helps. Every user builds a little avatar, a Townie, and Greze credits that relationship for the word of mouth and for how willing users are to get on the phone. The team spends hours a week doing exactly that.
The inbox stops being somewhere you go
Ask Greze where this ends and he describes one agent, maybe two, per person, tuned to your preferences and unambiguously on your side. "This is an agent that you pay for, that is for you," he said, drawing the contrast with a product like Facebook, where you can't tell whether it works for you or for the advertisers.
The diagnosis underneath it is about triage. "Your inbox has become a broad notification channel that doesn't distinguish between like highly important and requires your brain, highly important and does not require your brain, not even important." An agent that knows your preferences can make those distinctions for you. In Greze's version of the day you don't open your inbox ten times; the agent filters, hands you a Gmail link for the things it can't handle, and tells you it's forwarding three sales leads to the right account managers in five minutes unless you say otherwise. He already lives part of this with Slack, down to about three visits a day, with his agent summarizing what he missed and a click through to the raw thread when the summary isn't enough.
The habit he's betting against is weaker than it looks. Greze told Fortune that the 80th percentile user opens ChatGPT or Claude at most three times a day. Most people are not living in an assistant. They're living in an inbox that pings them.
The multiplayer version is a privacy problem
Everything above is single player. Email isn't. Greze had just given an AIE talk on agent-to-agent interaction and data silos, and his framing is that a company is a pile of silos, your email, my email, HR's data, what the PMs are working on, the codebase, that no single person can see, for good trust and privacy reasons. Agents cut against that, because trajectories get better the more data the agent can reach. "How do we give agents access to data in a way that doesn't destroy trust and privacy with human beings" is the question he thinks every multi-user agent product is walking into.
His proposal is to let an LLM inside each silo decide what's safe to publish into shared company data. The worked example is sales. Someone at your company already emails a buyer at the prospect you're chasing. LinkedIn will tell you who is connected; it won't tell you who has the relationship. An agent could answer that question without disclosing a single conversation: three colleagues, each with something like a 0.9 relationship score for that CFO, which is all you need to know who to ask for the intro. A relationship score is the kind of derived signal nobody would object to putting in a company-wide store, even though the inbox it came from stays off limits. Individuals are already doing a version of this for themselves with the personal wiki an AI maintains about them, consulted alongside third-party sources.
He expects the permission model to loosen the way coding agents' did. Dangerously-skip-permissions YOLO mode gave way to auto mode, where you trust the model to flag that a command is about to delete rows in the production database and ask first. In two or three years, Greze thinks you'll set policies on what your agent may share and let it exercise judgment about releasing information from your silo or your company's. He knows how that sounds. His answer is that agent behavior can be defined and trained "so that it's actually probably better judgment on average than a human being in a company today".
What this means if you're building one
Town's constraint list reads like a permission spec rather than a feature list, and the ordering appears to be working: a $55 million Series A led by Andreessen Horowitz in June 2026, with Forerunner Ventures, First Round, Alt Capital, and Conviction participating.
If you're shipping an agent that touches a system other humans can see, decide the default write permission before you argue about the model. Town picked drafts, published the ladder out of drafts, and made the user hold the key at every rung. That's a smaller product than the demo version. It's also the one people keep using: Fortune reported Town approaching 10,000 users, with 99% retention over two months among people who had built even one automation. Town is at town.com.
This interview was recorded at the AI Engineer World's Fair 2026 in San Francisco.