Skip to content

How to use Elevated Mode for host execution

I often find myself hitting a wall when my agent is stuck inside a sandbox. It is frustrating when you need to run a script or manage a process on the actual host machine, but the environment keeps you locked away for security. You want the flexibility to step out of that sandbox without manually reconfiguring the entire system every time you have a specific task to finish.

That is why I recommend using the /elevated directives. It lets you move execution from the sandbox to the gateway host on the fly.

Before you try these commands, make sure your configuration allows them:

  • The global feature gate tools.elevated.enabled must be true.
  • Your sender ID must be in the tools.elevated.allowFrom allowlist.
  • The specific agent must have agents.list[].tools.elevated.enabled set to true if that section exists.

You can change your elevation level for a single message or for your entire session. Here is the fastest way to get moving.

If you want every command in your current chat to run on the host, send the directive as its own message.

/elevated full

I prefer full when I want to skip execution approvals and just get the work done. If you want to keep the approval prompts, use /elevated on instead.

If you only need host access for one specific command, include the directive at the start of your message.

/elevated full check the disk space on the host

If you forget which mode you are in, send the command without arguments to see the current state.

/elevated

When you are finished with host tasks, drop back into the sandbox.

/elevated off

If things aren’t working as expected, check these common issues from the logs and system responses:

  • Received a hint instead of a confirmation: This happens if you send something other than on, off, ask, or full. The system only accepts those four arguments.
  • Actionable error message: If the directive replies with an error, you are likely not on the allowFrom allowlist or the feature is disabled in the global config.
  • Discord permissions: If you haven’t defined tools.elevated.allowFrom.discord, the system falls back to your channels.discord.dm.allowFrom list. I suggest explicitly setting tools.elevated.allowFrom.discord to avoid confusion.
  • Tool policy denials: If a tool is blocked by your global tool policy, /elevated cannot override that. Elevation only changes where the tool runs and the approval flow.

If you need more help setting up your environment, check out the AI Setup Assistant.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.