How it works

An agent's own log can leave things out. The cloud's record does not.

A signed log proves a record was not changed, not that it is complete: an action the agent never wrote down passes every integrity check. Remit checks the agent against the record the cloud keeps. The idea in three minutes: Is the log all of it?

WARRANT

A person signs what the agent may do.

Which agent, which actions on which resources, for how long, and why. An agent can hand on part of its warrant, and a delegation can only narrow.

BROKER

The cloud itself says no.

The agent holds no standing credentials. The broker turns a warrant into short-lived credentials limited to it, stamped with the warrant's id on every call, so the cloud refuses anything outside it.

RECONCILE

Every action, checked against the cloud's own record.

In both directions: an action outside any warrant becomes a finding, not an absence. The signed report says what each warrant was used for.

WITNESS

A history nobody can quietly rewrite.

Warrants and reports go into a log that independent witnesses co-sign. A warrant that is not in the log is never honoured. Ours is public.

Get started

Five minutes to see it, an afternoon to run it for real.

Download a signed binary for Linux or macOS from the latest release (each has build provenance you can check with gh attestation verify), or build it with Rust. Then, in your project:

remit init
remit task \
  --grant 's3:ListBucket=arn:aws:s3:::my-bucket' \
  --for 1h --purpose "find last week's exports"

remit init sets up the project: the agent's key, a witnessed log, and the AWS role template, with your own signing key kept outside the project. remit task signs a warrant for one task, logs it, and makes it the agent's current one. The agent works through Remit's MCP server or its Claude Code plugin; the guide takes you through the rest, including how warrants fit a development workflow.

What it does not claim

The limits are part of the design.

  • It does not judge intent. A warranted action can still be the wrong one; Remit makes it attributable to the person who signed the warrant.
  • It only speaks for what the cloud records. AWS records management events by default and data events, such as reading an S3 object, only where you turn them on.
  • It does not stop someone using their own keys. Actions by identities Remit does not manage are counted in every report under their own name, not blocked.
  • Its known gaps are published. Among them: a warrant cannot yet be revoked before it ends. The threat model lists them all.
Work with us

Remit is free. Help putting it in place is not.

We design warrants and roles and set up reconciliation in your accounts, alongside the agent readiness audit. Start with the free readiness check, or tell us about your agents. Partners who want to deliver Remit to their own customers: contact-us@abacross.com.

More films on the films page and on YouTube. The code, the specification and the threat model are on GitHub.