US Federal News Bureau
Written by: Tathagata Sen
Updated 6:26 PM EDT, September 29, 2026

The Government Accountability Office (GAO) said it could not determine the extent of Department of Government Efficiency (DOGE) teams’ access to federal systems and data at six agencies, according to a September 29 report. The review covered DOGE access from March 2025 through September 2026.
GAO said the agencies did not provide enough information to determine the extent and level of that access or whether the systems and data were adequately protected.
According to FedScoop and NextGov/FCW, four of the six DOGE teams, across the Consumer Financial Protection Bureau (CFPB), Department of Education, Securities and Exchange Commission (SEC) and National Oceanic and Atmospheric Administration (NOAA), had access to more than 23 information systems collectively. The systems contained information related to human resources, finances, contracts and grants.
The Small Business Administration (SBA) and Department of Veterans Affairs (VA) did not provide the information GAO requested to identify which systems DOGE had accessed or the level of access granted.
At Education, one DOGE team member had access to agency systems and its IT network, but the department did not provide details on the level of access, according to reporting on the GAO findings. At the SEC, GAO received some information about privacy and cybersecurity training but not enough to determine whether required training or controls were met for access to specific systems, including one used to manage contracts.
According to the reports, the CFPB provided information about DOGE access to its systems. Officials said DOGE was granted access to 19 systems, with one member able to view, modify and delete records in the primary HR system and three having full access to a Microsoft access-management system, but only limited documentation on privacy briefings and security training.
The SBA did not identify the systems DOGE had accessed, while the VA did not provide a list of systems or the level of access granted.
For chief data officers (CDOs), the report highlights a basic data governance requirement: organizations need visibility into who can access sensitive data, which systems they can access and what level of access they have. Without that information, data owners cannot fully assess whether appropriate controls are in place.
The findings also reinforce the need for clear accountability around data access. As agencies give employees, contractors or embedded teams access to information across organizational boundaries, CDOs need processes for documenting permissions, monitoring access and establishing responsibility for protecting the data.
GAO said that without the requested information, Congress and the public lacked assurance that the six agencies had implemented controls to ensure DOGE team members appropriately secured information.