A school can spend heavily on security vestibules, electronic locks, cameras and badge readers and still leave open a quieter vulnerability: the list of people whose credentials continue to unlock the door.
That is the pattern emerging from a statewide series of New York school building access audits released by the State Comptroller this summer. Across 14 reports issued over three consecutive Fridays from July 31 through August 14, auditors repeatedly found school districts and BOCES with active badges that were no longer needed, duplicate credentials, shared devices that could not be located, non-employee accounts that were not periodically reviewed and procedures that did not clearly assign responsibility for shutting access off.
The findings do not show that unauthorized people actually entered schools. The Office of the State Comptroller generally described the weaknesses as creating a potential risk of unauthorized access. But taken together, the audits move electronic building access out of the category of routine facilities management and squarely into the realm of school safety and internal control.
The question for districts is becoming less about whether the front door is locked and more about whether anyone can say, with confidence, exactly who still has the ability to open it.
The same problems are showing up in different districts
The latest Comptroller audits illustrate how the same control problem can appear in districts of very different sizes.
Brentwood Union Free School District, one of the largest districts examined in the August 14 batch, had 2,839 active building-access accounts, including 195 devices issued to nonemployees. OSC found three employees with duplicate active badges and five nonemployee badges that had not been disabled in a timely manner, even though district procedures called for disabling badges after four months of inactivity. Auditors said written procedures existed, but actual practices did not consistently follow them.
In Green Island, the numbers were smaller but the control problem was familiar. OSC found 12 active but unnecessary nonemployee accounts with badges. The district reviewed employee badges during the summer, according to the audit, but no one periodically reviewed nonemployee accounts, and written procedures did not clearly assign responsibility for managing and monitoring access.
Union-Endicott Central School District offered a more dramatic example. Its system included 1,675 active accounts associated with 742 devices issued to employees and 946 issued to nonemployees, including 447 shared devices. Auditors identified 19 nonemployee badges that should have been deactivated and 150 shared badges that were no longer needed. Thirty-five of those shared badges had been intended for substitute teachers and could not be located.
At East Rochester, OSC reported 983 active access accounts, including 646 nonemployee accounts. Auditors found 126 nonemployee badges they considered unnecessary, 88 people with duplicate active badges and 28 of 52 requested badges that district officials could not locate.
At OCM BOCES, auditors found 141 active individual nonemployee accounts and badges that were no longer needed, plus 86 shared badges that should have been deactivated. Officials could not locate 11 of the shared badges. OSC also found that officials had not independently verified background checks for 14 nonemployees who had direct contact with students and were given building-access credentials.
The same themes appeared in the August 7 audits of Broadalbin-Perth and Niskayuna and in the July 31 batch. Broadalbin-Perth had 42 shared nonemployee badges without expiration dates that were not being monitored to confirm they remained necessary. Niskayuna had 66 people with duplicate active badges and inconsistent tracking of shared credentials. In Batavia, auditors identified unnecessary employee, nonemployee and shared key fobs, including four shared fobs officials could not locate.
The technology is not the control
Electronic access systems are often treated as a security upgrade by themselves. They are not.
A badge system can be more controllable than a ring of physical keys because credentials can be programmed, restricted, logged and remotely disabled. But those advantages depend on governance. Someone has to authorize access. Someone has to know when a contractor's assignment ends. Someone has to deactivate a separated employee. Someone has to decide whether a coach, substitute, vendor or first responder still needs a credential. And someone has to periodically compare the system's active users against reality.
That is where many of the OSC findings converge.
The audits repeatedly focused on periodic reviews, written procedures, assignment of responsibility and the management of shared or nonemployee credentials. In other words, the weakness was often not the lock or the software. It was the handoff between human resources, facilities, security, technology, administrators and outside users.
That distinction is especially important as districts add wireless electronic locks, mobile credentials and centrally managed access systems. A more sophisticated system can create a larger inventory of permissions. If access expands faster than the district's ability to reconcile it, a security investment can accumulate its own control problem.
New York Mills Union Free School District provides a useful counterexample. OSC concluded that officials properly managed and monitored the district's 117 active accounts, noting that officials periodically reviewed active accounts, removed unneeded access and had written procedures. Yet auditors also found 177 first-responder badges had become inactive. The district reactivated them after OSC raised the issue.
That finding points to the other half of access control: good security is not simply turning credentials off. It is making sure the right people can get in when they need to.
What districts should do before opening day
The practical response is not complicated, but it requires ownership.
Districts should perform an access-control reconciliation between the active badge database and current personnel records before staff return, then separately review every nonemployee and shared credential. Contractors, vendors, substitutes, coaches, volunteers, former employees and temporary workers should not sit in a different universe simply because they are outside the regular employee file.
Each active credential should have an identifiable owner or defined function, an approval trail and, where appropriate, an expiration date. Shared badges should be minimized and checked out in a way that establishes who had them and when. Districts should also decide in writing which office is responsible for creating, modifying, reviewing and disabling access.
Periodic review matters as much as the opening-day cleanup. A once-a-year purge can miss months of unnecessary access. Districts can build badge management into employee separation procedures, contractor closeout, seasonal staffing changes and routine safety reviews.
The safest electronic lock is only as reliable as the district's answer to one basic question: Who can still open the door?
Comments (0)
No comments yet — be the first to share your thoughts.
Leave a comment