Vendor access control has a logic flaw: the Wilmington College voyeurism case shows what breaks when you outsource trust
Here's a failure mode that doesn't show up in your threat model until it does: a credentialed third-party worker with enough unsupervised building time to locate a ceiling access point, climb into a crawlspace above an occupied locker room, and start recording — all while your access control system showed nothing anomalous, because technically he was supposed to be there.
That's not a hypothetical. Jayson Barker, a janitor employed by a third-party custodial vendor at Wilmington College in southwestern Ohio, was arrested after a member of the women's soccer team spotted him photographing players from inside a ceiling space above the Scheve Athletic Center locker room, according to NBC News. He was charged on 11 counts of voyeurism. The college terminated its contract with the vendor following the arrest. Barker posted $22,000 bail with a return court date of October 5. Investigators are still evaluating whether similar conduct occurred previously. The student who looked up wasn't a detection system. She was luck.
The trust delegation problem
When an institution signs a custodial vendor contract, it is typically offloading more than cleaning. It is delegating the entire personnel vetting chain for everyone who will carry a key or credential to the building. That delegation usually lives in a single contract clause — "vendor conducts background checks on all employees" — and then goes completely unverified downstream.
This is a textbook case of trust without attestation. The institution assumes the vendor ran adequate checks. The vendor runs whatever baseline process keeps their cost-per-site down. Nobody audits the delta. The result is a trust chain with an unverified node sitting right at the point of physical access.
Standard commercial background screenings often flag felony convictions while missing misdemeanor voyeurism offenses, civil restraining orders, or prior terminations-for-cause from other facilities roles. A vendor operating across dozens of accounts may run an identical baseline check for a janitor assigned to a loading dock and one assigned to a locker room in an athletic center. The institution has no visibility into that unless it explicitly contracts for it.
What a correctly-designed access control policy looks like
Institutions that handle third-party worker access rigorously treat it as a layered system rather than a single gate. Three components:
Position-specific screening tiers. A contractor assigned to sensitive spaces — locker rooms, medical facilities, dormitory common areas — should clear a more thorough screen than one working in an administrative building. That screen should include sex-offender registry checks in every state where the individual has lived, not just the vendor's state of incorporation.
Verified process, not assumed process. Require vendors to document what their screening covers. Write an audit right into the contract. Some institutions now require vendors to submit screening results directly to the institution's security office for any worker assigned to a sensitive access category. If you can't audit it, you don't know if it's running.
Credential review cycles. A background check at onboarding is a point-in-time snapshot. Workers holding long-term facility credentials to sensitive spaces should be rescreened — annually at minimum. This isn't standard practice yet, but it's increasingly recommended in campus security frameworks, and incidents exactly like this one are why.
The escort policy gap
Credential oversight covers who should be in a space. Physical supervision covers whether someone can exploit the time they're legitimately in it. High-sensitivity spaces should have either a staff escort policy during cleaning windows, or real-time access log monitoring that flags entries outside those windows. Both are operationally straightforward. Neither requires significant capital outlay. What they require is a decision to implement them before an incident forces the conversation.
The crawlspace above that locker room had a physical entry point. If anyone had mapped service corridor and ceiling access points as part of a patrol schedule during contractor hours, the deterrent effect alone changes the calculus for someone considering that entry. That's not a surveillance problem — it's a scheduled physical presence problem.
XGuard for operators building physical security programs
If you're building or running physical security operations — dispatch platforms, patrol scheduling systems, contractor credentialing workflows, or facility security programs — XGuard is the real-time marketplace and dispatch infrastructure worth knowing about. It connects facilities operators with licensed, vetted security personnel on-demand, with scheduling and patrol coverage that can be scoped to exactly the kind of blind spots this case exposed: service corridors, utility access points, and back-of-house mechanical areas during contractor hours. For operators designing layered physical security programs, XGuard is worth a look at what the dispatch and coverage model looks like under the hood.
What the audit looks like right now
Pull your active vendor list. Identify every contractor holding credential access to a locker room, training room, medical suite, or dormitory common space. For each one: confirm what background screening was conducted, when it was last updated, and whether your contract gives you any visibility into that process. Then pull access control logs — or physical key sign-out records if electronic systems aren't in place — for entries in those sensitive spaces outside posted cleaning schedules in the last 90 days.
Pro tip: Position-specific background screening requirements can be added to vendor contracts at renewal without renegotiating base pricing. Draft policy language is available through the Association of College and University Housing Officers and ASIS International's campus security working group. Adding it costs nearly nothing. The Wilmington case illustrates what the absence of it can cost.
Campus security personnel detained Barker until police arrived — correct response at point of detection. The structural work is what happens before detection is necessary: knowing who holds credentials to which spaces, what vetting actually covered, and whether the institution verified any of that or just assumed a vendor already had.
The access control failure here wasn't a technical exploit. It was an assumption that went unaudited long enough for someone to climb into a ceiling.
Source: NBC News — 2026-09-26
Originally published at xguard.app. This version was adapted for this platform's audience; the canonical original lives at the link above.












