



GAO reviewed DOGE team access at six agencies and found that four, the CFPB, Department of Education, NOAA, and SEC, reported their DOGE teams had access to more than 23 systems containing contracts, grants, HR data, finances, and personally identifiable information. GAO could not determine whether DOGE staff had specific permissions to view or modify that sensitive data because the information provided was insufficient.
Two agencies, the Small Business Administration and the Department of Veterans Affairs, did not respond at all to GAO's requests for information about which systems their DOGE teams accessed. The agencies that did respond, CFPB, Education, and SEC, gave only limited documentation on whether IT security controls were actually followed, and NOAA, SBA, and VA gave no information on controls whatsoever.
GAO states plainly that it has statutory authority to obtain this information and that agencies' stated reasons for withholding it do not diminish that right. CFPB disputed the report's accuracy; GAO says it stands by its findings.
The full dispatch is available from the source below.