Looker’s new role-management assistant ships with an instance-support contradiction
The 26.16 release note assigns the preview to Looker (original), while Google’s operating guide says it requires Looker (Google Cloud core) and is unavailable on original instances.
Google is beginning the Looker 26.16 rollout with a useful but unresolved deployment question: which Looker product can actually run the new Admin Assistant? The first-party release note and the linked operating guide give opposite answers.
What the release note says
Google’s September 4 release note says Looker 26.16 is expected to begin deploying September 8 and finish by September 20. Under the heading “Looker (original) only changes,” it lists the Admin Assistant as a preview feature that uses natural language to manage Looker roles. Google Cloud: Looker release notes
That placement tells administrators to expect the capability on Looker (original), not Looker (Google Cloud core). But the linked documentation says the reverse.
What the operating guide says
The Admin Assistant guide states that users “must be using” a Looker (Google Cloud core) instance and explicitly says the feature is not available for Looker (original). It also excludes Cloud core instances configured for private connections only. Additional prerequisites include enabling Gemini in Looker, turning on Trusted Tester features, enabling Admin Assistant in Looker’s Admin panel, and assigning the user a Looker Admin role. Google Cloud: Manage Looker roles with the Admin Assistant
The assistant can search roles, permission sets and model sets; list permissions and LookML models; and propose new role configurations. Google cautions administrators to verify every suggested role, permission-set or model-set change before creating or editing it. The preview caps returned records at 100, initially shows 25 items, displays only the six most recent conversations and limits user queries to 1,000 words. Google Cloud: Admin Assistant guide
What administrators should do
This is not a cosmetic documentation mismatch. The two instance types have different deployment and networking models, and the guide’s private-connectivity exclusion affects environments that deliberately restrict external paths. Until Google reconciles the pages, teams should not treat the 26.16 release-note placement as proof of eligibility.
The safe rollout sequence is to check the actual instance type, confirm whether it is private-connections-only, verify that all documented Gemini and Trusted Tester controls are present, and test in a non-production role configuration. Generated permission changes should remain proposals for human review—not direct policy decisions—because Google’s own guide requires verification.
The feature’s value is clear: natural-language inspection could shorten the work of navigating complicated Looker role structures. But access-control automation needs a firmer product boundary than the launch documentation currently provides.
sources
- Looker release notesdocs.cloud.google.com
- Manage Looker roles with the Admin Assistantdocs.cloud.google.com
comments · 0