The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Treasury described DOGE-affiliated access to its payment systems as read-only in early February 2025. A later Government Accountability Office review found that one employee briefly had permission to create, modify, and delete data in one system because of a permissions error. GAO found no evidence that the employee changed system data. Its findings also distinguish that employee’s direct access from a second employee’s indirect, staff-mediated access.
What Treasury said—and what GAO later found
In February 2025, Treasury told a U.S. senator that a member of its DOGE team would access Bureau of the Fiscal Service (BFS) payment systems to assess their integrity and business processes. Treasury publicly characterized the access as read-only.
GAO later reviewed access requests, accounts, assigned roles, system logs, and agency officials’ explanations for the period January 20 through April 11, 2025. Its report, GAO-26-108131, describes the access findings as preliminary results of ongoing work. GAO identified two Treasury DOGE team employees with access, but their access was not the same: one had direct system access and the other relied on BFS staff to display information.
What the employee with direct access could do
GAO found that one employee had direct access to view, copy, and print data in three payment systems, as well as to read a copy of system source code. The table summarizes the access GAO says was granted. It does not establish that the employee viewed every record available in a system.
#1 Best Overall
| System | Data access | Permission to change data | Source-code access |
|---|---|---|---|
| Payment Automation Manager | Personally identifiable information (PII) | Could not create, modify, or delete data | Could read a copy |
| Secure Payment System (SPS) | PII | Temporarily could create, modify, or delete data from January 31 to February 1, 2025; afterward could not | Could read a copy |
| Central Accounting Reporting System | Non-PII data | Could not create, modify, or delete data | Not stated in GAO’s table |
| Automated Standard Application for Payments | No access to data | Not stated in GAO’s table | Could read a copy |
For the brief SPS period, GAO found that an administrator granted incorrect permissions after confusion about an amended request. Treasury officials said the requester had amended the request multiple times; the final SPS entry said read/write, and the administrator was confused about what to grant. BFS officials did not believe the employee knew about the elevated permissions. GAO found no evidence that the employee changed system data while they were active.
BFS removed that employee’s access on February 6, 2025. The temporary SPS permission does not mean every DOGE-affiliated person had write access, or that the employee altered payment records.
Rank #2
A second employee had indirect access
A second employee did not have an independent account. Instead, the employee could ask BFS staff to open payment systems and show specific data—an arrangement GAO described as “over the shoulder” access. Because activity was not logged directly to that employee, BFS could not provide a comprehensive list of the systems accessed this way.
Why the security findings matter
GAO assessed 14 applicable controls in four areas using federal information-security guidance. BFS had implemented five of the 14 selected controls. GAO rated system access partially implemented, system integrity fully implemented, and information confidentiality and system-usage monitoring substantially implemented. It recommended six actions to address weaknesses.
Recommended Free Tools
Rank #3
Among the weaknesses GAO identified, BFS did not ensure that one employee agreed to follow its IT security rules before receiving a BFS laptop. Security tools were also not configured to identify and block unencrypted payment information.
GAO further found that an employee sent payment information to two GSA DOGE team members without encryption or prior BFS approval. The file covered USAID payments made between January 22 and January 24, 2025, and included names and payment amounts for more than 350 people. That finding concerns the handling of a particular file; it does not, by itself, establish that the information was misused.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the court order did
On February 21, 2025, the U.S. District Court for the Southern District of New York issued an order in New York v. Trump that restrained Treasury and the Treasury secretary, pending further order, from granting DOGE-affiliated employees, officers, or contractors access to Treasury payment records, payment systems, or other Treasury data systems containing payees’ personally identifiable or confidential financial information. The order also required Treasury to report on training, vetting, mitigation, employment authority, and reporting chains. The order is reproduced by Justia.
The Oregon Department of Justice litigation tracker says the district court modified the preliminary injunction on May 27, 2025, and that federal defendants filed a notice of interlocutory appeal on July 31, 2025. As of October 8, 2026, the tracker lists Second Circuit oral argument for October 19, 2026, a future date. It does not establish the outcome of that argument.
What the record establishes
- Treasury’s early-February public description was read-only, but GAO later documented a temporary write-permission error for one employee in SPS.
- GAO found no evidence that the employee changed system data while that permission was active.
- One employee had direct access to data in three systems; a second could obtain information indirectly through BFS staff, in a way that was not comprehensively logged to the individual.
- GAO identified control weaknesses, including the unencrypted transfer of a file containing names and payment amounts for more than 350 people.
GAO summarized the stakes this way: “The integrity and security of these systems are critical to the nation’s economy and to the security of sensitive personal and financial information.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




