Skip to content
Home » Seneca County » State audits find building access weaknesses at Waterloo, Groton schools

State audits find building access weaknesses at Waterloo, Groton schools

State audits find building access weaknesses at Waterloo, Groton schools

State auditors found weaknesses in how the Waterloo and Groton central school districts managed electronic building access, including unnecessary active credentials, duplicate badges or key fobs and gaps in procedures for reviewing who could enter school buildings.

Separate August audits from the Office of the New York State Comptroller concluded that neither district properly managed and monitored all building access accounts and devices. Auditors said the deficiencies created a potential risk of unauthorized entry, though the reports did not identify an incident in which an unauthorized person used one of the credentials to enter a school.


The scale of the findings differed sharply between the districts. Waterloo had 1,170 active building access accounts during auditors’ April 2026 fieldwork, while Groton had 179 active accounts when auditors conducted fieldwork in February.

Both audits covered the period from July 1, 2024, through Nov. 30, 2025, with the review periods extended into 2026 to examine access activity logs. Both districts generally agreed with the comptroller’s recommendations and began corrective work during or after the audits.

Waterloo had more than 1,100 active access accounts

Waterloo’s system had 1,170 active accounts, including 491 devices issued to current employees and 679 issued to non-employees. Of the non-employee credentials, 491 were shared devices.

Auditors found 106 people had two or more active badges. That included 86 employees and 20 non-employees. Eight employees and two non-employees had at least three active badges.

Among Waterloo’s 390 current employees, 86 — or 22% — had at least two active badges. Auditors examined 31 badges assigned to eight employees who had three or more and found district officials could not locate 12 of them.

The district’s network analyst told auditors that certain employees, including custodians and administrators, were routinely given two badges for convenience. The eight employees examined by auditors had also lost badges and received replacements, but the original lost badges were left active in case they were later found.

Auditors said lost badges should instead be deactivated as soon as possible and warned that leaving missing credentials active increased the risk that someone could use one for unauthorized entry.

Waterloo officials were reviewing a daily events report for suspicious activity, but auditors found they weren’t routinely using other available reports to identify badges that had gone unused or were no longer necessary.

Dozens of Waterloo non-employee badges were unnecessary

The comptroller’s office also found 56 of Waterloo’s 679 non-employee badges, or 8%, were no longer needed.

Thirty-three were shared badges with little or no activity. Twenty hadn’t been used in at least six months, while 13 had never been used. Another 23 were assigned to individual non-employees, including 17 former vendors, four former employees and two community members who had been given access to use school facilities.

Nine of those 23 badges had never been used.

Auditors also found 20 individual non-employees with at least two badges. Two had three active badges apiece. When auditors asked the district to produce those six badges, officials couldn’t locate three.

Overall, Waterloo officials could not locate 37 of 78 badges requested by auditors, or 47%.

The comptroller’s office attributed the problems partly to a lack of clearly assigned responsibilities and procedures for reconciling active accounts against lists of people who still needed access.

Waterloo did have written procedures governing the issuance, modification and deactivation of employee badges. Auditors found, however, that there were no comparable procedures for monitoring or deactivating non-employee badges and no requirement to regularly review all active accounts.

At the time of the audit, the network analyst and a computer support specialist could create, modify and deactivate access. Requests generally came from the district’s human resources department or administrators by email.

The network analyst told auditors he planned to establish a process under which non-employee accounts would be deactivated after 30 days of inactivity. During the audit, he also reviewed the district’s active accounts and deactivated credentials identified as unnecessary, shared or duplicate.

Waterloo says some employees need multiple credentials

Waterloo partially disagreed with the comptroller’s broader concern about employees holding more than one access device.

The district said some jobs require both an identification badge and a key fob for operational, safety and security reasons. It also noted that identification badges can wear out or break through regular use, making replacements necessary.

Still, Waterloo acknowledged that stronger controls were needed to document and monitor replacement or duplicate credentials and deactivate those that were no longer necessary.

The district agreed that the 56 unnecessary non-employee credentials identified by auditors should have been deactivated and said those devices have since been disabled.

Waterloo also agreed with auditors’ finding that 37 of the 78 requested badges couldn’t be located. The district said all unaccounted-for badges were disabled and that it was strengthening inventory and tracking procedures.

District officials also offered additional context for the large number of non-employee credentials. Waterloo maintains more than 100 access devices for first responders, including local fire departments, emergency medical services and law enforcement agencies, allowing them to enter district facilities during emergencies.

The district said those devices serve public safety needs but agreed they should be reviewed periodically to ensure they remain authorized and appropriately assigned.

Groton audit found eight unnecessary non-employee key fobs

Groton’s access system was substantially smaller, with 179 active accounts during auditors’ fieldwork. That included 159 key fobs issued to 157 current employees and 20 issued to non-employees.

Auditors found one employee — the district’s maintenance supervisor — had three active key fobs. District officials said the supervisor needed multiple devices because of his emergency responsibilities.

The comptroller’s office nevertheless recommended that the district consider limiting employees to one device, saying additional active key fobs increased the possibility of one being lost or stolen.

The larger issue in Groton involved non-employees.

Eight of the district’s 20 non-employee accounts, or 40%, were deemed unnecessary. Five were assigned to vendors and had never been used. Another belonged to a project manager and hadn’t been used for at least two years.

Two more were shared key fobs assigned to BOCES and an accounting firm. Neither had been used, and district officials couldn’t locate them.

After auditors raised the issue, the maintenance supervisor deactivated all eight unnecessary non-employee key fobs.

Groton lacked a formal review process

Groton had a system for issuing employee credentials but lacked written procedures clearly establishing who was responsible for managing and monitoring access.

New employee accounts were created by the maintenance supervisor after the district clerk processed employment paperwork. The supervisor also created non-employee accounts, changed access at the request of district leaders and revoked employee access after being notified by administrators or secretaries.

Elementary and high school secretaries were expected to collect key fobs from departing employees, according to the maintenance supervisor, who relied on them to tell him which devices should be disabled.

But auditors found there was no comparable process for ending non-employee access when it was no longer needed.

No one was periodically reviewing all active accounts to determine whether the credentials were still necessary, even though reports already available in the district’s access system could be used for that purpose.

Auditors said that was why officials were unaware that the missing shared BOCES and accounting firm key fobs were still active or that other non-employee credentials had become unnecessary.

Groton’s superintendent had assigned the maintenance supervisor responsibility for managing the system. Although other district officials had administrative rights, auditors found no one served as a backup who could activate, modify or deactivate accounts if the supervisor was unavailable.

Groton adopts new procedures, quarterly reviews

Groton generally agreed with the four recommendations but said some positions may still require multiple key fobs.

The district agreed that credentials should be disabled and collected as soon as they are no longer necessary and said it had been disabling identified key fobs during the audit period.

Officials also agreed to create written procedures defining who manages and monitors accounts and shared devices. The district said those procedures would be completed before the beginning of the 2026-27 school year.

Groton also said it was moving to quarterly reviews of active access accounts.

The corrective procedures included notifying the facilities supervisor of personnel changes after Board of Education meetings, immediately deactivating access for employees no longer actively working on school grounds and immediately disabling lost or stolen badges before replacements are issued.

Comptroller recommends similar changes in both districts

Despite the differences in size and number of questionable credentials, the comptroller made essentially the same four recommendations to Waterloo and Groton.

Auditors urged both districts to reconsider issuing multiple access devices to employees, deactivate unnecessary accounts and recover credentials promptly, establish written procedures defining responsibility for monitoring building access, and regularly reconcile active accounts using system reports.

The comptroller’s audit criteria also call for credentials to be individually assigned whenever possible, shared devices to be avoided or closely tracked, lost and stolen devices to be immediately deactivated, and access inventories to be periodically reconciled.

Waterloo’s five school buildings each have a single public entrance, with employees able to use additional secured entrances with authorized credentials. Groton has two school buildings, also with a single public entrance at each and additional secured entry points available to employees.

The comptroller characterized electronic access controls as one part of a broader school security system. The audits focused specifically on management of credentials and didn’t assess every aspect of physical security at either district.

The Waterloo Central School District covers portions of Fayette, Junius, Seneca Falls, Tyre and Waterloo in Seneca County. Groton’s district stretches across portions of Cayuga, Cortland and Tompkins counties, including the towns of Locke, Summerhill, Homer, Dryden, Groton and Lansing

The boards of education in both districts are responsible for initiating corrective action. Under state requirements cited in the audits, each district must provide the comptroller’s office with a written corrective action plan addressing the findings and recommendations, with implementation beginning by the end of the next fiscal year to the extent practicable.



Tags: