ELDRED — A state audit found that the Eldred Central School District did not properly manage and monitor building access badges, creating a potential risk of unauthorized access to district buildings.
The audit, released June 5 by New York State Comptroller Thomas P. DiNapoli’s office, reviewed the district’s building access accounts and devices from July 1, 2024 through Nov. 30, 2025. Auditors also reviewed access activity logs through Dec. 17, 2025.
According to the audit, the district uses a building access management system with 252 active building access accounts, including 196 devices issued to current employees and 56 issued to non-employees. The district’s three school buildings each have a single public point of entry, while employees and staff may use additional secured entry points that require a badge.
Auditors found that 41 district employees had two or more active badges. Four employees were assigned as many as four active badges, and Superintendent of Schools Traci Ferreira was assigned seven active badges at the time of the audit fieldwork in December 2025.
The audit also found seven non-employee badges that were not tracked or disabled when no longer needed. Those included five shared badges and two active badges assigned without a business need to a Board of Education member and a retired bus driver.
District officials also could not locate 14 active badges, including 13 duplicate employee badges and one shared badge, according to the audit.
“District officials did not properly manage and monitor building access accounts and devices,” auditors wrote. “As a result, there was a potential risk for unauthorized access to District school buildings, compromising building security and safety for students, teachers, staff and visitors.”
The Comptroller’s office found that while the district had a process for adding access accounts for employees and non-employees, no one periodically reviewed active accounts to determine whether they were still needed. Auditors said the issues occurred because district officials had not clearly assigned responsibility for managing and monitoring accounts or developed written policies and procedures for issuing and monitoring badges.
The audit made four recommendations, including that the district deactivate accounts and collect badges as soon as they are no longer needed, ensure employees do not have duplicate badges, develop written procedures assigning responsibility for badge management and create a reconciliation process to review active accounts and badges.
In response to a request for comment from the Democrat, the district provided a written statement saying it recognized in July 2025 that a review of its policies and procedures for creating, issuing and destroying building access badges was necessary.
“Upon receiving the audit data, the district took swift action to resolve all immediate vulnerabilities regarding active access badges,” the district stated.
According to the district, all secondary badges identified in the audit have been located, deactivated in the system and physically destroyed. The district also said seven active badges assigned to non-employees were immediately deactivated, and any badges that could not be physically located were deactivated in the system.
The district said the Director of Technology, in coordination with the Human Resources Secretary and Superintendent of Schools, conducted a full audit of the system database. Duplicate accounts, former employee accounts and accounts tied to lost badges have been permanently deactivated, according to the statement.
The district also said it has initiated a formal off-boarding process to ensure that when an employee, contractor or vendor leaves the district, their access badges are deactivated and collected without delay.
“The Superintendent, Administrative Cabinet, and Director of Technology reviewed all system access groups,” the district stated. “We have established strict, standardized access parameters tailored specifically to the requirements of each employment position.”
The district said the administration will review badge access parameters annually, including a reconciliation process across all user groups to ensure accounts are monitored and aligned with district building security protocols.
“The district remains committed to maintaining a secure environment and believes these decisive steps will prevent future discrepancies while hardening our overall facility security,” the statement said.
The district is required to prepare a written corrective action plan addressing the audit’s findings and recommendations and provide it to the Comptroller’s office within 90 days. The corrective action plan should also be posted on the district’s website for public review.
