GuidesRunning & maintaining

“OpenClaw change was cancelled because its run ended”: the approval card, explained

In OpenClaw 2 an agent cannot edit its own configuration: it proposes an OpenClaw change and you approve it. Why a proposal lapses when the agent's turn ends, what “approved and applied” means, and how to ask so it lands first time.

September 5, 2026The Everpod team
The short answer

In OpenClaw 2 your agent does not edit its own configuration. When it wants to change a setting, a built-in system agent that speaks as “OpenClaw” files the change as a typed operation and waits for the owner to approve it. “OpenClaw change was cancelled because its run ended” means the agent’s turn finished before you answered, so the pending change was dropped rather than left dangling. Ask again, and this time reply while it is waiting: a plain “yes” is enough. “OpenClaw change approved and applied” is the success message, and for most settings it takes effect at once with no restart.

What you are looking at

The two lines arrive in the same chat as the agent’s ordinary replies, marked with a warning sign and a tick:

⚠️ OpenClaw change was cancelled because its run ended
✅ OpenClaw change approved and applied

They are not from your agent. They come from what the docs call a “built-in system agent” that “speaks as ‘OpenClaw’” and handles “local setup, repair, and configuration” (it was called Crestodian before the 2.0 rename). When your agent decides a configuration change is the right response to what you asked (a new default model, a setting it needs), it hands the change to that system agent instead of writing the file. The system agent shows a plan, something like “Plan: restart the Gateway. Reply /openclaw yes to apply,” and does nothing until an owner says yes.

Why it was cancelled

The proposal lives inside the run that made it. The docs are specific: “If that run ends or loses authority during preparation, OpenClaw stops before starting the next persistent write,” and the result is “a non-applied outcome instead of leaving the agent reporting a pending change.” In practice that means the agent asked the question, you read it, and by the time you typed a reply the agent had already finished its turn and moved on. The change is dropped on purpose. A half-approved edit to a running agent’s configuration would be worse than no edit. Pending write approvals also expire on their own after 15 minutes, so an approval typed the next morning has nothing to approve.

Here is the sequence as we watched it on one of our own machines, on OpenClaw 2026.9.1 over Telegram. The owner asked the agent to make a different model its default. The agent proposed the change; the owner read it, and the turn ended first: the warning line appeared. The owner asked again, and this time typed “approved” while the proposal was open. The tick line appeared, the configuration reloaded within a second, and no restart was needed. One detail worth knowing from that same session: the conversation kept answering on the model it had been pinned to with /model -s until that pin was cleared, because a session-scoped pick outranks the default. The default had changed; the chat in front of us had its own opinion.

What counts as approval

The approval is deliberately unforgiving. The docs describe “a closed deterministic list” of accepted replies, phrases like “yes,” “sure,” “go ahead,” and “not now” to decline, and the permission-modes page adds the sentence that explains the whole design: “conversational claims of approval never authorize the change.” Your agent saying “the owner agreed” authorizes nothing. Only a message from an explicit owner identity does; the docs rule out “wildcard sender rules, open group policy, unauthenticated webhooks, or anonymous channels” as sources of a yes. A session running with full access applies its operations automatically, which is the one configuration where you will never see the card.

The reason is the one that governs every agent with tools: an agent that can rewrite its own configuration is an agent that a poisoned web page can reconfigure. Routing every change through an owner-approved, audited operation (“every applied rescue operation is audited”) closes that door without taking the capability away.

Getting it to land first time

Your own cloud agent, set up for you.

Everpod runs OpenClaw on a private, always-on computer of its own: set up, secured and backed up, with model usage included. You name your agent, and say hello about fifteen minutes later.

Create your agent

First month half price, then $29/mo · model usage included · cancel anytime

Wondering what you’d do with one? See what a cloud agent can do