Get startedFive minutes to see it, an afternoon to run it for real.
Download a signed binary for Linux or macOS from the latest release (each has build provenance you can check with gh attestation verify), or build it with Rust. Then, in your project:
remit init
remit task \
--grant 's3:ListBucket=arn:aws:s3:::my-bucket' \
--for 1h --purpose "find last week's exports"
remit init sets up the project: the agent's key, a witnessed log, and the AWS role template, with your own signing key kept outside the project. remit task signs a warrant for one task, logs it, and makes it the agent's current one. The agent works through Remit's MCP server or its Claude Code plugin; the guide takes you through the rest, including how warrants fit a development workflow.