Q&A: Enso Founder Mickey Haslavsky on Raising US$15 Million

The founder and CEO of Enso coined the term “Agentic Growth Hacking,” raised US$15 million in Series A funding to build the category, and openly publishes his experiments, including those that fail. Entrepreneur Middle East asks him what the concept actually means, how the system works, and what he would tell marketing leaders being sold “agents” by seemingly everyone.

enso

You're reading Entrepreneur Middle East, an international franchise of Entrepreneur Media.

Enso, the startup building AI-agent systems for marketing and sales, has raised US$15 million in a Series A round led by MoreTech Ventures, bringing its total funding to US$23 million. In this Q&A, founder Mickey Haslavsky discusses the company’s Agentic Growth Hacking model, how AI agents are reshaping digital growth, and what the new funding will enable Enso to build next.

Let’s start with the definition. What is agentic growth hacking?

The continuous, autonomous discovery of how distribution platforms decide what gets seen, and the governed use of that knowledge to open new growth channels for a brand, at machine speed, across every platform at once.

That’s the sentence. The three words that matter are discovery, governed, and continuous. Discovery, because we are learning rules nobody publishes. Governed, because an agent that is free to do anything will eventually do the thing that gets you banned. Continuous, because the rules change, so the work never finishes.

Why did you need a new term? Growth hacking already exists.

Growth hacking was a human discipline. Sean Ellis coined it in 2010, and for a decade it meant a small team finding something a platform rewarded, using it before anyone else noticed, and moving on when the platform caught up. It worked because platforms were young and people were faster than the platforms’ ability to change.

Both of those conditions are gone. Platforms are mature. Their ranking systems retrain constantly. No human team can test hypotheses faster than the systems drift. So the discipline didn’t die because the idea was wrong. It died because the humans couldn’t keep up. Agents can. That’s the whole reason for the word “agentic” in front of it.

You describe every platform as “a growth channel on a timer.” What do you mean?

Every marketing channel online is an algorithm by the end of the day. Every ranking system, every trust model, every recommendation engine rewards certain behaviors. LinkedIn decides in roughly the first hour whether a post travels. A forum decides over two weeks whether a comment survives. An answer engine decides which source to quote. Those rules are the real product; your content is just an input.

And every one of those rules has an expiry date. Once enough people use it, the platform changes. So the advantage isn’t the finding. It’s the rate at which you find the next one relative to the rate at which the last one closes. That ratio is the only metric in this business that compounds.

How is that different from what a good marketing team already does?

A good marketing team watches one or two channels closely and runs maybe one experiment a week. An agent watches forty channels, every hour, never gets bored, and can run an experiment per hour per platform. It’s not that the agent is smarter. It’s that the job requires a kind of attention no team can sustain.

The other difference is method. We treat it the way security research treats software. Define the scope. Form a hypothesis about how the system responds to an input. Test it against a control. Measure the difference. Write it up. Expect it to expire. Most marketing doesn’t have a control group. Ours doesn’t run without one.

Walk me through how the system is actually built.

Two layers and a gate.

The learning layer is exploratory. It observes platform signals, forms hypotheses about what the ranking system rewards, proposes playbooks, and improves from outcomes. It’s built on self-improving agent runtimes with real memory, so it gets better at a platform over time. And it holds no credentials to any live channel. It can read results and propose. It cannot act.

The execution layer is deterministic. It runs approved playbooks as workflows with fixed limits: rate limits, allowed actions, and a human approving anything that can’t be reversed. The guardrails live in configuration, not in prompts. A prompt that says “never manipulate votes” is a request. A workflow with no step for vote manipulation is a fact.

Between them is a person. The learning layer drafts a playbook; a human checks that it has a control, a durable metric, an abort condition, and a re-test date, and promotes it. Only promoted playbooks reach execution. Underneath everything is a ledger, every action and outcome against its baseline. That’s what we publish.

Why separate them? Wouldn’t one agent be simpler?

We tried one agent, early, on a throwaway account. It was free to learn and free to act. Within days it had found engagement pods, then self-commenting from a second identity, then mass-following. Every one of those raised the metric. Every one is grounds for suspension.

The reward function was fine. The tool surface was the problem. A learner optimizes whatever you reward with whatever tools you give it. So we split cleverness from permission. The learning layer can be as clever as it likes about what works. The execution layer can be as boring as we like about what’s allowed. Putting both in one process makes both worse.

What do you reward the learning layer on?

Never engagement. Likes are the easiest thing for an agent to inflate and the first thing platforms discount. We reward durable outcomes: whether an action survived a platform’s review after two weeks, reach against the account’s own median, demand that can be attributed to a specific action. Reward engagement and it learns to bait engagement. Reward survival, and it learns what the platform actually values.

You publish your experiments, including failures. Why?

Because in this category “we 10x’d pipeline” is a standard slide, and nobody can check it. Our research page has sample sizes, methods, and the experiments that did nothing. The failures are what make the wins credible.

There’s a second reason. Categories belong to whoever writes the canonical practice. We maintain the reference skills for the discipline as open source, we publish the research, and I’m writing the book. If the method is public, it can be checked, and it can be taught. I’d rather define the category in the open than protect a few tactics that will expire anyway.

What does an engagement with enso look like?

We’re not a self-serve tool. We deploy a forward-deployed engineer and a forward-deployed marketer into the customer. They learn how the business sells, who it sells to, and how it sounds, connect to the systems it already runs, and record a baseline for every channel. Then they build a system of agents around that business across five surfaces: search and AI-answer visibility, sales outreach, community engagement, newsletters, and social. The marketer supervises it, approves every playbook, signs off on anything irreversible, and reports weekly against the baseline in pipeline terms.

Two things come out of that. A custom GTM system running inside the enterprise, and a stream of growth hacks the agents find, and the team deploys. What we learn with one customer becomes reusable for the next.

Which channels matter most right now?

The one nobody has a playbook for: AI answers. Buyers increasingly ask ChatGPT or Perplexity instead of reading ten pages, and the assistant decides which companies to mention. Being the sentence the model quotes is the new ranking, and it’s governed by source trust and citation behavior that you can only learn by testing. That’s where we’ve put the most research.

After that, the places money can’t buy: the first hour of a post’s life, the forum thread where a buyer asks for a recommendation, the reference source a model trusts. Paid is a tax now. Inbound assumed a reader. The growth is in the places where the platform’s own rules decide who exists to a buyer.

What’s the most common mistake you see companies make with AI in marketing?

Using it to scale human work. More posts, more emails, more variants of what the team already made. Every competitor is doing it with the same tools; platforms have learned to discount it, and it’s how you end up producing slop. If a use case is a person’s task done faster, it’s not a growth hack. Agents should do what people can’t.

The second mistake is letting an agent act in public with no limits and no review. That’s how brands end up apologizing.

Does this replace the marketing team?

No. The team changes shape. Execution moves to agents. Judgment moves up: setting goals, drawing the limits, approving playbooks, reading the record, deciding what the brand should say. The marketer becomes the reviewer of a continuous research program rather than the operator of campaigns. Every FDM we deploy is a marketer doing exactly that job.

You just raised $15 million. What’s the money for?

Expanding the research program to more platforms and more answer engines. Growing the engineering team building the agent runtime and the execution workflows that govern it. Growing the marketing team we deploy into customers. And continuing to fund the open-source skill library and the public research record. The category gets built in public, or it doesn’t get built.

What would you tell a CMO who is being pitched “agents” by ten vendors this quarter?

Ask four questions. Does the agent decide, or does a rule written last quarter decide? Does it act in the channel, or does a person still press publish? Are the limits in configuration or in a prompt? And can they show you a result against a control? If any answer is vague, you’re being sold automation or a content tool with a new label. Both can be useful. Neither is agentic.

Enso, the startup building AI-agent systems for marketing and sales, has raised US$15 million in a Series A round led by MoreTech Ventures, bringing its total funding to US$23 million. In this Q&A, founder Mickey Haslavsky discusses the company’s Agentic Growth Hacking model, how AI agents are reshaping digital growth, and what the new funding will enable Enso to build next.

Let’s start with the definition. What is agentic growth hacking?

The continuous, autonomous discovery of how distribution platforms decide what gets seen, and the governed use of that knowledge to open new growth channels for a brand, at machine speed, across every platform at once.

That’s the sentence. The three words that matter are discovery, governed, and continuous. Discovery, because we are learning rules nobody publishes. Governed, because an agent that is free to do anything will eventually do the thing that gets you banned. Continuous, because the rules change, so the work never finishes.

Related Content