Last updated 2026-09-04Development preview

Use Control Room

Find previews, access reviews, flags, and operational status in your customer-owned Control Room.


Control Room is the operational UI installed in your GCP project. It brings together the products enabled for that customer installation. The hosted Platform portal manages your Fluffy account, organization, and entitlement separately.

#Understand: a view of several systems

A preview has a source revision and a lifecycle. A temporary access request has a provider grant state. A flag has a published configuration revision. Control Room presents those facts together, but the selected system still determines their meaning.

For example, an approved access request may still be waiting for provider activation. A restored audit record is historical evidence, not a new permission. Check the resource, application, environment, and revision before acting on a status.

#Configure: open the correct installation

Use the URL printed by Premium installation, then sign in with an identity allowed by its configuration. Confirm the installation and selected application/environment. Navigation depends on enabled capabilities and available application bindings.

Opening Control Room does not require adding code to your application. Product setup may require configuration or runtime grants; follow the guide for the operation you need.

TaskWhere to workEvidence to check
Review or stop a PR environmentPreviewsRepository, commit, lease and lifecycle state
Request, approve, deny, or end resource accessExact Google PAM link from the packageHuman identity, physical resource, duration and provider grant state
Review an emergency incidentResource Access retrospective reviewIncident, justification and supporting timeline
Edit, publish, or roll back flagsFlags configurationApplication, environment and configuration revision
Inspect flag exposure analyticsConfigured flag analyticsRevision, variation and data freshness
Inspect application signalsEnabled observabilityMonitor/counter, application revision and available traffic

The preview, access, flag, and observability chapters explain the underlying configuration. Control Room is not a general shell or SQL administration console.

#Recover Resource Access records

An organization owner can separately enable hosted backup in the Platform portal. This option copies normalized Resource Access operational records—requests, incidents, reviews, and audit records—under the configured hosted boundary.

Use the portal's restore authorization and the customer Control Room recovery flow. Check the target installation and restored history. Restoring those records does not create a Google PAM grant, restore an application's PostgreSQL data, or recover deployment credentials.

For application database recovery, use the separate database recovery guide. There is no general CLI backup command implied by the hosted record-backup option.

#Reference: missing or stale information

What you seeWhat to establish
A product section is absentIts capability is enabled and its target bindings exist
A permission errorCorrect Google identity and installation group membership
Access approval shown, grant pendingCurrent PAM state and provider propagation
An old preview revisionThe requested commit and the corresponding build result
No recent observability dataThe monitor's scope, traffic, deployment and data freshness
A restored access requestWhether it is historical evidence or linked to a currently active provider grant

Follow the exact provider link when resolving a provider decision. Control Room does not impersonate a human approver. Installation service removal uses the reviewed Premium CLI uninstall workflow; application deployment and account subscription remain separate operations.