
Four agencies reported giving DOGE teams access to more than 23 systems collectively. Thomas Fuller/SOPA Images/LightRocket via Getty Images
Agencies withheld records needed to verify DOGE data safeguards, GAO says
A review of six agencies could not establish the full extent of DOGE’s system access or whether security rules were followed. Two agencies challenged the watchdog’s authority to investigate.
Six federal agencies failed to provide records needed to determine whether Department of Government Efficiency personnel appropriately accessed and protected government systems, leaving Congress and the public without assurances that sensitive information was secured, the Government Accountability Office said Tuesday.
The watchdog’s report details unanswered requests for system access records, user activity logs and evidence that DOGE personnel met security requirements. Some agencies explicitly refused further cooperation, with the Securities and Exchange Commission and National Oceanic and Atmospheric Administration disputing GAO’s authority to conduct the review.
Four agencies reported giving DOGE teams access to more than 23 systems collectively, including tools for managing contracts, grants, finances and personnel. But auditors could not independently establish the full extent of that access. The other two agencies — the Department of Veterans Affairs and the Small Business Administration — did not provide the information needed to identify which systems DOGE personnel could use.
“Without the ability to examine the requested information, Congress and the public lack assurance that these agencies implemented controls needed to ensure DOGE team members appropriately secured information,” GAO wrote.
The review covered the Consumer Financial Protection Bureau, Education Department, NOAA, SEC, SBA and VA, with audit work running from March 2025 through September 2026.
SEC and NOAA challenged GAO’s authority to conduct the review, while Education cited litigation and privacy concerns as reasons for not providing records. VA declined to provide records or explain why, and SBA left requests unanswered. GAO said those objections did not override its statutory authority or right to obtain records.
CFPB called the review a “fishing expedition” and said further requests were burdensome. Both CFPB and SEC reported no DOGE-related security or privacy incidents, but GAO said it lacked access to records needed to verify those assurances.
At CFPB, officials reported granting access to 19 systems. One DOGE team member could view, modify and delete information in the bureau’s primary human resources system. Three had full access to a Microsoft system used to manage user access.
CFPB said DOGE staff did not access systems containing market monitoring, supervision, enforcement or fair lending information. However, the report notes that two team members had sufficient permissions to grant themselves or others access to those systems, though the bureau said they did not do so.
At Education, one DOGE member reportedly received limited access to two Federal Student Aid systems and an administrative account on the department’s network. Auditors could not determine what privileges that administrative account provided.
NOAA said one detailee received permission to create, change and delete internal website content to remove material related to diversity, equity and inclusion. Other detailees received access to contract and grant systems, but GAO could not confirm the complete scope of their permissions.
The review shows that questions about DOGE’s access to sensitive government information remain unresolved more than a year after its teams entered and sought to overhaul the federal enterprise. Resistance from agency officials highlights the obstacles Congress’s watchdog faces in independently verifying how that access was used and controlled.
The review also left unanswered questions about basic personnel safeguards. Agencies supplied some training records and signed security agreements, but not enough to establish compliance across their DOGE teams.
The findings follow an April GAO review of DOGE access to Treasury payment systems that identified failures to follow security procedures, including an instance in which a DOGE employee improperly shared unencrypted information. The new report says Treasury’s Bureau of the Fiscal Service had not implemented any of the six recommendations from that review as of September.
Although the executive order establishing DOGE set a July 4, 2026, termination date for its temporary organization, GAO noted that it did not terminate the broader U.S. DOGE Service — a rebrand of the U.S. Digital Service established under the Obama administration.
Congress’ watchdog has repeatedly faced difficulties obtaining basic information about DOGE’s personnel and activities. A tally of 10 agencies and the Executive Office of the President had not supplied records GAO requested to verify whether DOGE employees completed ethics training and financial disclosures, according to an earlier oversight report. Missing information also prevented auditors from determining the appointment types of more than 150 personnel.




