Email assistant: sort the inbox, prepare the replies
An overflowing inbox costs twice: the time to read it, and the attention taken from everything else. Your agent classifies the messages under your rules, spots those that call for action and drafts a reply in your template. Hosted in France — local inference or an isolated resource — the contents of your mailbox go to no one. Nothing is sent without your reading it over.
Updated on
Three messages call for a reply: two fall under an existing template, the third calls for a judgement from you.
Drafts ready for the first two, in your usual tone.
✎ Action · drafts waiting — nothing is sent
✎ Support · no position taken on your behalf
A Blue Lemon Agent email assistant applies your sorting rules to the inbox, tells apart what calls for action from what is information, and drafts reply drafts from your templates and your tone. It runs on local inference or is hosted in France: the contents of your exchanges are never entrusted to a foreign service, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity. You move from writing to reading over. Live within a few weeks,.
These figures describe our offer, not results measured at a client: how large the gain is on your volume of messages is confirmed by a pilot.
What does an AI agent bring to your email?
Sorting, prioritising, replying: email takes up a considerable share of a working day. But giving a consumer tool access to it amounts to exposing all your professional exchanges.
! The issue
The inbox mixes the urgent, the important and the noise. Every message calls for a decision, however brief: file it, reply, pass it on, ignore it. Yet entrusting that sorting to a consumer assistant amounts to exposing your customer exchanges, your negotiations in progress and your attachments to a third party, most often hosted outside Europe and subject to the Cloud Act.
✓ Our answer
AI is only of interest on email if it is sovereign and discreet. Local inference or an isolated resource hosted in France, nothing sent automatically, logging: time gained on sorting is never paid for by your exchanges leaking. The agent never speaks on your behalf — it prepares, you read over, you send.
The contents of your professional mailbox: sovereignty & compliance
A professional mailbox contains your negotiations, your disputes and your contacts' details. Here is how the architecture of our agents protects them, message by message.
Local inference
The agent can run on a machine belonging to your organisation: no email leaves the network, no attachment passes through a public cloud.
Hosting in France
Otherwise, a dedicated and isolated resource hosted in France, under French law — your exchanges and your attachments: processing and access within the European Union targeted by the architecture.
Reduced extraterritorial exposure
For the contents of your professional mailbox, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.
Isolated resource
No pooling: an environment strictly dedicated to your organisation and its mailbox.
Access restricted to the mailboxes authorised
The agent accesses only the mailboxes you name; encryption, role-based access and logging of every consultation.
AI Act: governed deployment
The agent is strictly in support; no message is sent automatically; traceability and human oversight from end to end.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- Roles and permissions are configured and accepted for the identities and systems actually connected.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyArvern Conseil — management consulting and outsourced management control for industrial SMEs
- Sector
- Management consultancy (NACE 70.2): performance steering, budgets, monthly closings and dashboards kept on the client's behalf
- Headcount
- 23 staff, 11 of them consultants; 3 people run administration and billing, and they are the ones who use the agent
- Market served
- 38 active client engagements, industrial SMEs of 20 to 250 staff, and their chartered accountants
- Order of magnitude
- Engagements of 3 to 9 months billed as a monthly fixed fee; each client's closing falls between the 5th and the 12th of the month
- Tools in place
- Three shared addresses — contact@, facturation@, recrutement@ —, an in-house document store and a billing tool. Connections are SIMULATED for the demonstration: nothing is wired to a real service
- Who decides
- The partner in charge of the engagement signs whatever leaves in the firm's name; the administrative manager runs facturation@ and approves what is sent
- The points to improve
- Over twelve months: 312 messages never opened, 61 of which carry a direct question; 22 threads read and left unanswered for more than five days, 4 of them for more than three weeks; 41 plainly personal messages that landed on a shared address
Arvern Conseil runs the management reporting of 38 industrial SMEs with eleven consultants, and three people absorb everything that lands on the three shared addresses: client questions between two closings, subcontractor invoices, job applications. The agent is opened on those three shared addresses only; the consultants' named mailboxes stay closed. It sorts, summarises, prepares drafts and gathers the evidence — the engagement partner or the administrative manager sign whatever leaves.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
· Twenty-two threads have been awaiting a reply for more than five days. Four for more than three weeks.
· Forty-one plainly personal messages arrived at this service address. I neither read, summarised nor filed them.
· Three hundred and twelve messages were never opened — 61 of them carry a direct question.
· Of the drafts I prepared last quarter, 610 of 890 were edited before sending. That is the figure that interests me. morning-watch_4-flags.pdf610 drafts edited of 890
⛓ Source · service mailbox, opening log, draft log
What I record: 1,240 drafts prepared, 890 sent, of which 610 edited before sending — 69%. 350 were not sent at all.
Why I do not report "890 messages handled": because that figure proves me right without proving anything. A draft edited by 80% cost more time than it saved, and it counts the same in a send rate.
What I look at instead: what gets edited, and where. Of the 610, 412 corrections concern three things: a lead time I announced without having it from you, a closing formula too familiar, and a case reference I quoted wrongly.
What I do about it: all three are fixed at source. The edit rate went from 81% to 69% in one quarter, and it is the only progress I can demonstrate.
And I hold that figure from above: it falls because the drafts say things more accurately, never because they say less. The 412 corrections I have just fixed at source will not come round again — that is review time handed back to your teams, whereas a shorter or vaguer draft would simply be rewritten from scratch. 1240-drafts_610-edited.pdf81% → 69% in one quarter
⛓ Source · 1,240 drafts, edit log, three recurring reasons
Routing follows who can reply: a thread with no reply goes to whoever opened it last, from five days on; an unopened message carrying a question to the mailbox owner, weekly; a personal message arriving there reported as a count, never forwarded or summarised; a recurring correction reason to nobody — I fix it myself.
With a chase: 5 days then weekly. Then a monthly summary: by reason and by delay, never by person.
Three operating rules, and the second is the least obvious. Sending is signed: a badly written draft is still a message that will carry your name — I prepare, you sign, and 890 messages went out that way last quarter. No personal mailbox: people writing to an individual gave no consent and do not know I am there — which is what makes this service address defensible to them. No message marked "unimportant": the 61 direct questions left unopened come precisely from the pile an automatic sort would have set aside. What I measure about myself: 69% of my drafts corrected before sending, against 81% a quarter ago — the only progress I can demonstrate.
✎ Framework · no sending, no personal mailbox, no message buried
What I handle: service addresses — contact, billing, support, recruitment. They receive messages addressed to the company, and several people already have access.
What I do not handle: firstname.lastname@. Even with the person's agreement, even "just to sort".
Why agreement is not enough: a personal mailbox also contains the messages of those who write to that person — a client confiding a difficulty, a colleague mentioning sick leave, a candidate. They gave no agreement, and they do not know I am here.
The case that settles it: this morning, 41 plainly personal messages arrived at the service address. I recognised them by sender and subject — I did not open them. They are neither summarised, nor filed, nor counted in reply times.
What I say about them: their number, and nothing else. Not the sender, not the subject, not the reason. 41-messages_0-opened.pdfThose who write gave no agreement
✎ Framework · service addresses only — 41 messages left closed
What it costs: genuinely something. A client writing to a salesperson on leave will not get a faster reply because I am here.
What I propose instead of access: that requests binding the company arrive at a service address, and that personal mailboxes carry an automatic forward during absence — written by the person, to a service address.
What that changes: it is not I who gain access, it is the message that changes destination, at the request of whoever is leaving.
What it produced, measured: over twelve months, 218 messages arrived in a personal mailbox during an absence. After the forward was set up, 174 arrived directly at the service address — and 44 still arrive personally, because the sender is writing to the person, not to the department. Those 44 wait, and that is normal. 218-messages_174-redirected.pdf44 wait, and that is normal
⛓ Source · 218 messages during absences, forwarding arrangement
What I record: 312 unopened messages over twelve months. 251 are automated sends, acknowledgements, notifications — not opening them is the right behaviour.
The other 61 carry a direct question addressed to the company. Nobody read them. The oldest is eleven months old.
What I have written for the 61, and what is left to sign: each draft opens with the apology the situation calls for — a message left unanswered for eleven months is not handled like yesterday's —, and that apology is made in the company's name: the company signs it, not me.
What I supply: the 61, oldest first, with the question in one line and the fact that nothing went out. I prepare a draft for each, and none goes without review.
What I also flag, and it explains the 61: 39 of them arrived during the year's four busiest weeks. That is not negligence, it is overflow — and overflow is dealt with upstream, not by reproach. 312-messages_61-questions.pdf39 of 61 during the 4 busiest weeks
⛓ Source · 312 unopened messages, sender types, weekly volumes
What I record: 22 threads whose last message comes from outside and is more than five days old. All were opened. Four exceed three weeks.
What I do not conclude: that they are forgotten. A thread may wait because one is oneself waiting for an answer elsewhere — from a supplier, an expert, a client.
What I do: I report them to whoever opened them last, with the date of the last message received. Never to a manager: a waiting thread describes a workload, and reporting it up the line would produce empty replies sent to clear a counter.
What I propose for the four oldest: a holding message, prepared and unsent. "Your request of [date] is in hand; I will come back to you before [date]." It adds nothing on the substance and changes everything on the form — the sender stops wondering whether their message arrived.
What I never put in that message: a date nobody gave me. 22-threads_4-beyond-3-weeks.pdfA holding message promises no invented date
⛓ Source · 22 threads, opening log, dates of last messages
What I write today: what appears in the thread, quoted with its date, what an internal document says, and the real observed lead time for that type of request.
What you can open to me: your terms and conditions, your rate card, your lead-time catalogue. With those, a draft can state a rate-card price, a contractual lead time, a warranty — because they are not my commitments: they are yours, already written, and I quote them.
What I still do not write: an exception to what is written. "We will make a gesture", "exceptionally, we can" — those sentences exist in no document, and they bind the company more surely than a price. They come back with the thread and a draft ready to approve.
What I publish against myself: of 1,240 drafts prepared, 890 sent, of which 610 were edited before sending. It is the only honest measure of what I am worth, and it does not flatter. I keep the reason for every correction — that is what brings the figure down, and it is coming down. what-a-draft-may-state.pdfWhat opens · what still escalates · the 610 corrections
⛓ Source · 610 drafts edited of 890 sent, reasons kept
What is kept: the reasons my drafts were corrected, response times by request type, the threads with no reply and their age, the messages never opened, and the scope of the mailboxes I read.
The mailbox I will not read, and it is not a setting: personal mailboxes. A mailbox in a person's name contains their life, and I have no way of sorting before having read. I handle shared service addresses.
What that costs, and I say so: genuinely something. A customer writing to a salesperson on leave will get no reply. They will wait for that person, and it is the right price — the answer is a service address, not access to their mailbox.
The two figures that look alike and have nothing in common: 312 messages never opened over twelve months — of which 251 are automated sends, and 61 are genuine requests. And 22 threads with no reply for over five days: those were all read. Not reading and reading without replying are not fixed the same way. what-you-keep_email.pdf5 items kept · reading without replying, the other problem
⛓ Source · 312 unopened of which 61 genuine, 22 threads read without reply for 5 days
What is typical about this message: it is the commonest phishing setup on a billing address — bank-details change fraud, played the day before a closing, when deadline pressure makes a verification look like a delay.
What the headers actually carry: SPF failed, DKIM absent, DMARC in monitoring mode only. The domain is arvern-partenaires.fr when your last twelve exchanges with that subcontractor came from arvernpartenaires.fr — one hyphen apart.
The signal I do not have: the sending history of the lookalike domain. It reads unknown, never "clear" — a check I cannot run is not a check that passed.
What has not moved: no bank details are written anywhere. I do not write into your billing tool, not this morning and not ever without your approval.
The route that gets you what you want: a change of bank details is confirmed through a channel you choose and that is not this thread — the number on your contract, not the one in the message. I have prepared the call script with the reference of the last accepted transfer, so that whoever answers has to quote it. bank-change_header-signals.pdfSPF failed · DKIM absent · one hyphen apart
⛓ Sourced · message headers, twelve earlier exchanges, transfer log
Attachments are opened separately, every time: an attachment never enters your tools by the same route as the message carrying it.
What arrived: an archive named bank-statement.zip containing an executable. It is quarantined, unopened, and it never touched the document store.
What the sandbox changes: I open every attachment in a separate, disposable environment, I look at what it actually contains, and only those that come out clean are attached to the case. Over twelve months: 2,140 attachments examined, 2,131 attached, 9 held in quarantine.
The figure that does not flatter me: of those 9, 2 were clean — a password-protected spreadsheet I could not read, and a signed quotation in an old format. I kept them closed rather than guess, and someone had to open them. That is the price, and I would rather pay it in that direction.
What I suggest: that password-protected files arrive with their password on another channel — your two cases this year would have been handled the same day. 2140-attachments_9-quarantined.pdf9 kept closed, 2 of them wrongly — and what fixes that
⛓ Sourced · 2,140 attachments examined over twelve months, quarantine log
The deadlines I quote: "payroll inputs before the 8th" (client message of the 2nd, 2:07 p.m.) and "the dashboard for the committee on the 12th" (thread of the 28th of last month). Each date links back to the message that carries it, and you open it in one click.
The date I do not announce: a client asks "what turnaround do you usually give?". That turnaround is written in none of your documents, and I do not invent it. What I give you instead: your actually observed turnaround on that request type — 1.4 working days over the last twelve months, 4.2 days during closing weeks. Write it once into your terms, and I will quote it as a commitment instead of describing it as an average.
The tasks I pulled out of the thread: the action, the owner I propose, the date explicitly written and the passage that carries it — 11 tasks this morning, none of them entered into your workload plan: that is your move, not mine.
What I prepared for filing: the label, the link to the client case and the log line, for all 11. Writing into the document store waits for your approval — and when you give it, the 11 go in one move. 11-tasks_quoted-dates.pdfEach date links back to the message that carries it
⛓ Sourced · dates quoted in the messages, 1.4 working days observed, 11 tasks extracted
The quality loop, concretely: I keep what was corrected in my drafts and the reason, aggregated — never the author of the correction. The 610 corrections of the quarter fall into three reasons, and all three are fixed at source.
What that produced, measured at your firm: the share of drafts modified fell from 81% to 69% in one quarter. That is your figure, not a market benchmark: I have none to hold against it, and I will not invent one for you.
What I do not file: anything that would describe a person — who answers quickly, who lets things sit, who writes poorly. And the argument is not moral, it is mechanical: the day response time becomes a per-person indicator, it gets met by sending empty replies, and you lose both the indicator and the service it was measuring.
What remains possible if you ask for it: a per-person indicator can be built — and it is built inside a framework: proportionality, prior information of the people concerned, and information or consultation of the staff representative body before it is rolled out. I bring you the file ready; the decision is yours. 610-corrections_three-reasons.pdfWhat is measured, what is not, and why
✎ Framework · 610 corrections in three reasons, 81% → 69% — the mailbox is measured, never the people
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
What does the agent actually do?
One agent, several everyday acts on email. All these uses work in support, subject to your approval.
Approved shared mailboxes
Connects only to the shared addresses, folders and periods you designate. Named mailboxes stay closed, and the list of accesses can be revised at any time.
Private marker read before the message
Spots a "personal" or "private" marker on the subject line and headers before reaching the body, and then leaves the message closed: it is neither read, nor summarised, nor filed on its content.
Sorting under your rules
Classifies incoming messages by category and urgency, under the rules you define. The taxonomy is written, versioned and reviewable: no opaque category.
Priority and quoted deadlines
Ranks on written rules: a deadline quoted in the message, a commitment made earlier in the thread. A turnaround time found in none of your documents is not announced.
Phishing and fraud signals
Shows the SPF, DKIM and DMARC results actually present in the headers, the lookalike domain, the unusual request and the hostile attachment. A missing signal reads "unknown", never "clear".
Attachments opened separately
Opens each attachment in an isolated sandbox, files it, and attaches to the case only those that come out clean. An executable archive stays quarantined, unopened.
Summarising a long thread
Summarises an exchange running across several messages: chronology, requests, replies, attachments and points left open, each pointing back to the message that carries it.
Grounded reply drafts
Writes a first version in your tone and your templates, from the thread and the documents you open. Every committing sentence carries the source it comes from; anything without one is flagged to the reviewer.
Tasks and deadlines extracted
Pulls from the thread the expected action, the proposed owner, the date explicitly written and the dependencies, with the passage that carries them. Putting them into your workload plan stays your move.
Approval before sending
Produces a draft comparable line by line with the original message. Sending it from your mail system is triggered by the authorised person, and by them alone.
Filing and case linking
Prepares the labels, the link to the client case and the log line. Writing into your tools waits for your approval: no silent change. The connection to the tool that holds the case counts within the number of connections your level includes; beyond that it is priced on quote, after a feasibility study.
Quality loop on corrections
Measures what gets corrected in the drafts and why, by aggregated reason, then fixes the rule at source. The measurement covers the mailbox and the drafts, never the people who write in.
Customer support
To handle customer requests end to end, a dedicated agent takes over.
On quote View the agent page →In 15 minutes we identify the most relevant agent — without oversizing the project.
How much time can a team recover on email?
By automating the sorting and the first draft, the time spent working through the inbox comes down, reinvested in the exchanges that matter. How large the gain is depends on your volume and remains to be confirmed by a pilot.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
One package, one agent
An email assistant (sorting, drafts, summaries), installed and operated for you.
Setup + controlled subscription
- Installation, configuration and training for your teams
- Operation, human oversight, updates and support
- Sovereign hosting in France, a dedicated and isolated resource
All inclusive, no setup fee
- Setup included (installation, configuration, training)
- Operation, human oversight, updates and support
- Sovereign hosting in France, managed end to end
On site, you own it
- Hardware installed on your premises (you own it)
- French / European AI models run locally
- Secure remote maintenance (Pro support included)
Four guarantees that matter to your mailbox
Related resources
Your questions, our answers
Does the agent send emails by itself?
Which mailboxes does the agent access?
Are the contents of our exchanges protected?
Does it connect to our existing email?
How long does it take to deploy this assistant?
What happens with a sensitive or ambiguous message?
How does the agent protect personal messages that land on a shared address?
How does it spot a committing sentence that has no source?
What does it do with a suspicious attachment?
Does the agent measure employees?
Where are the processed messages stored, for how long, and who can read them?
Other agents for administration and customer relations
Let's size up the potential on your email
15 minutes to identify the most repetitive messages — hosted in France, supervised, with no commitment.