Brentwood Union Free School District – Building Access (S9-26-12)

Issued Date
August 14, 2026

[read complete report – pdf]

Audit Objective

Did Brentwood Union Free School District (District) officials properly manage and monitor building access accounts and devices?

Audit Period

July 1, 2024 – November 30, 2025

We extended our audit period to April 14, 2026, to review access activity logs.

Understanding the Audit Area

Building access controls are essential for enhancing security and enabling school officials to manage and monitor entry points within educational institutions. These systems authenticate a user through devices such as key fobs, keycards, badges, or similar technologies, helping to ensure only authorized individuals can enter school buildings. By limiting access in this way, schools can better safeguard their facilities and maintain a safe and secure environment for students, teachers, staff and visitors.

The District utilizes a building access management system (system) with 2,839 active building access accounts (accounts), including 2,644 devices issued to current employees and 195 issued to non-employees, of which eight are shared badges.1 Each of the District’s 17 school buildings has a single public point of entry. Employees may also access the buildings through additional secured entry points, which require a device for entry. The Safety Office, led by the Director of Safety (Director), was responsible for device management at the District during our audit period.

Audit Summary

District officials could improve how they manage and monitor building access accounts and devices (badges). Although the District had written procedures for building access and badge management that included details regarding the issuance, monitoring and disabling of badges, they were not always followed because the current District practices did not match the written procedures. As a result, there was a potential risk for unauthorized access to District school buildings, compromising building security and safety for students, teachers, staff and visitors. Specifically, of the accounts we reviewed, the District had active, but unneeded, accounts with assigned badges in the system:

  • Three District employees had duplicate active badges.
  • Five non-employee badges were not disabled in a timely manner despite the District’s badge management procedures stating officials should disable badges with four months of inactivity.

Although District officials had a process for periodically reviewing active accounts to determine whether they were needed, they did not disable all accounts with inactivity in a timely manner. These issues occurred because District officials did not follow the District’s written procedures that clearly described and assigned responsibilities to the Safety Office personnel for managing and monitoring accounts.

This report includes three recommendations that, if implemented, will help District officials improve management and monitoring of building access accounts and badges. District officials generally agreed with our recommendations and their response is included in Appendix B. Appendix C includes our comment on an issue raised in the District’s response.

This audit was conducted pursuant to Article V, Section 1 of the State Constitution and the Office of the New York State Comptroller’s (OSC’s) authority as set forth in Article 3 of the New York State General Municipal Law (GML). The audit’s methodology and standards are included in Appendix D. 

The Board of Education (Board) has the responsibility to initiate corrective action. A written corrective action plan (CAP) that addresses the findings and recommendations in this report must be prepared and provided to OSC within 90 days, pursuant to Section 35 of GML, Section 2116-a (3)(c) of the New York State Education Law and Section 170.12 of the Regulations of the Commissioner of Education. To the extent practicable, implementation of the CAP must begin by the end of the next fiscal year. For more information on preparing and filing the CAP, please refer to the OSC brochure, Responding to an OSC Audit Report, which was provided with the draft audit report. The CAP should be posted on the District’s website for public review.


1 A shared account or device is assigned to a user for a specific role or function but not assigned to a specific individual (e.g., vendors or first responders).