The Scattered Castles database is the Intelligence Community’s central record of who holds a security clearance, what level they hold, and which Sensitive Compartmented Information compartments they are read into. Governed by Intelligence Community Policy Guidance 704.5, it is the system a security officer queries before letting you into a sensitive facility, and it is where your eligibility determinations, polygraph history, and any denials or revocations live.1Office of the Director of National Intelligence. Intelligence Community Policy Guidance 704.5 – Intelligence Community Personnel Security Database Scattered Castles If you work in or around the IC, this is the record that follows you.
What Scattered Castles Records About You
ICPG 704.5 requires the database to hold several categories of information for each cleared person:1Office of the Director of National Intelligence. Intelligence Community Policy Guidance 704.5 – Intelligence Community Personnel Security Database Scattered Castles
- Every eligibility determination, including approvals, denials, revocations, and suspensions.
- Any waivers, deviations, or conditions attached to a clearance, which matter later for reciprocity.
- Current SCI and controlled access program holdings, meaning the specific compartments you are indoctrinated into.
- Collateral clearances, background investigations, and adjudications conducted by IC elements, including pending and cancelled actions.
- Polygraph completion dates and types.
- Crossover clearances granted when you move between IC elements.
Most users see the data read-only. Only the parent agency that granted the clearance or conducted the investigation can write to your record, which stops one organization from altering another’s findings. IC elements are required to push updates at least weekly for routine actions like briefings, debriefings, and interim clearances. Denials, revocations, suspensions, and reciprocity inquiries have a tighter deadline of 24 hours.1Office of the Director of National Intelligence. Intelligence Community Policy Guidance 704.5 – Intelligence Community Personnel Security Database Scattered Castles
In sensitive cases, an IC organization may enter you under a pseudonym. When they do, the source organization keeps separate internal records tying the pseudonym to your true identity.
Who Can See Your Record
Access is limited to organizations within the Intelligence Community as defined by the National Security Act of 1947. The major users include the CIA, NSA, DIA, NRO, and the intelligence arms of the FBI and State Department, along with other entities designated by the President or jointly by the DNI and a department head.1Office of the Director of National Intelligence. Intelligence Community Policy Guidance 704.5 – Intelligence Community Personnel Security Database Scattered Castles Each IC element’s leadership decides who inside their organization gets an account.
One practical gap matters if you work for a contractor. ICPG 704.5 does not explicitly authorize direct access for contractor Facility Security Officers at private firms, so many DoD industry FSOs cannot pull Scattered Castles records at all. If you are moving from a defense contract into IC work, expect your gaining agency’s security office to pull the record on your behalf rather than your FSO doing it directly.1Office of the Director of National Intelligence. Intelligence Community Policy Guidance 704.5 – Intelligence Community Personnel Security Database Scattered Castles
How Scattered Castles Relates to DISS
Scattered Castles is not the government’s only clearance database, and it does not automatically sync with the other one. The Defense Information System for Security carries the bulk of DoD personnel, including military members, civilian employees, and defense contractors with collateral clearances up to Top Secret.2Defense Counterintelligence and Security Agency. Defense Information System for Security Scattered Castles focuses on people who hold or need access to SCI and other controlled access programs within the IC.3Army G-2. Scattered Castles
Because the two systems do not share data in real time, you can hold an active Top Secret/SCI in Scattered Castles while DISS reflects only a Secret clearance, because the SCI portion was granted by an IC element rather than a DoD component. A verification in one system does not guarantee the other is current. If your work straddles IC and DoD roles, expect security managers to check both, and expect occasional friction when the two records disagree.
Verification and Visit Certifications
The verification itself is simple. A security officer logs into the secure portal, enters your identifying information, and runs a query. If a record exists, the system displays your current access level, investigation dates, and any conditions or restrictions on eligibility. If no record exists, the officer gets a no-hit result, which means either you have no IC clearance on file or your record sits only in another system like DISS.
The officer then compares the displayed access against what the position or facility requires, and logs the transaction. Those audit logs create the accountability trail federal inspectors use to confirm that no one was granted entry to classified spaces without a current, valid clearance.
Scattered Castles is also the primary source for visit certifications. When you need to visit another IC facility, the receiving security office can pull your record directly instead of waiting on a hard-copy or electronic visit request from your home organization. Hard-copy certifications are still accepted when the database is unavailable, but the query is the default, and it cuts days off what used to be a slow administrative process.1Office of the Director of National Intelligence. Intelligence Community Policy Guidance 704.5 – Intelligence Community Personnel Security Database Scattered Castles
Reciprocity When You Change Agencies
Reciprocity is the policy that stops the government from investigating you all over again every time you move. Intelligence Community Directive 704 requires IC security elements to accept in-scope personnel security investigations and access eligibility determinations from other agencies, provided those determinations are free of conditions, deviations, or waivers.4Office of the Director of National Intelligence. Intelligence Community Directive 704 – Personnel Security Standards and Procedures for Access to SCI
Security Executive Agent Directive 7 sets the clock. Agencies must make reciprocity determinations within five business days of the personnel security program receiving the file for processing, and agency heads are personally responsible for making and recording those determinations within that window.5Office of the Director of National Intelligence. Security Executive Agent Directive 7 – Reciprocity of Background Investigations and National Security Adjudicative Determinations Employment suitability or fitness processing sits outside this clock; SEAD 7 only governs the national security reciprocity determination itself.
Two things stretch the five-day standard in practice. First, if your Scattered Castles record shows a condition, deviation, or waiver, the receiving agency has legitimate grounds to look harder rather than rubber-stamp the eligibility. A condition attached for a past financial issue, for example, changes the calculus. Second, when the receiving security office needs the full investigative file from the originating agency, SEAD 7 gives investigative service providers ten business days to respond. Delays compound.
What Happens If Your Access Is Denied or Revoked
When an agency denies or revokes SCI access, that decision must be recorded in Scattered Castles within 24 hours, and it stays in the system for 50 years from the date of the action. Every security officer who queries your name during that half-century will see the entry. Because the database also functions as a National Agency Check data source, the denial or revocation will surface during any later background investigation, no matter which agency runs it.1Office of the Director of National Intelligence. Intelligence Community Policy Guidance 704.5 – Intelligence Community Personnel Security Database Scattered Castles
Adjudicators evaluate eligibility against 13 guidelines set by Security Executive Agent Directive 4, covering areas like allegiance, foreign influence, financial considerations, criminal conduct, drug involvement, alcohol consumption, personal conduct, psychological conditions, handling of protected information, and outside activities.6Office of the Director of National Intelligence. Security Executive Agent Directive 4 – National Security Adjudicative Guidelines A negative determination under any of them can trigger a denial or revocation.
Appealing a Denial or Revocation
The process is heavily weighted toward the government but you are not without recourse. You must receive a written explanation of the basis for the decision, as detailed as national security permits. You can hire an attorney at your own expense, request the documents and investigative records that underlie the decision, and submit a written reply within 45 days of receiving that documentation. If the initial review does not resolve the matter, you can appeal to a high-level panel of at least three members, two of whom must come from outside the security field. The panel’s decision is generally final, unless the head of the IC element personally exercises authority based on the panel’s recommendation.
The government has 30 days to provide requested documents, and classification can limit what is disclosed. You may never see the full basis for a denial if the underlying information is classified or would reveal intelligence sources.
Can You See Your Own Record?
Not really. The Office of the Director of National Intelligence has invoked broad exemptions under subsections (j) and (k) of the Privacy Act, 5 U.S.C. 552a, to shield personnel security records from the standard access and amendment rights that normally apply to federal records about you.7eCFR. 32 CFR Part 1701 Subpart B – Exemption of Record Systems Under the Privacy Act
Under those exemptions, ODNI is not required to give you an accounting of who has accessed your record, let you see or correct it, or publish procedures for notifying subjects that records exist. The stated rationale is that access could alert individuals to investigative interest, compromise classified information, or breach confidentiality promises made to people who provided information during your background investigation.7eCFR. 32 CFR Part 1701 Subpart B – Exemption of Record Systems Under the Privacy Act The ODNI’s information management office can exercise discretion to waive an exemption if doing so would not interfere with counterterrorism or law enforcement interests and is not prohibited by law, but discretionary waivers are uncommon. Most requests will be denied or heavily redacted.
Where Continuous Vetting Is Taking This
The old model of a periodic reinvestigation every five or ten years is being replaced. Under the Trusted Workforce 2.0 initiative, the federal government is moving to continuous vetting, which monitors cleared individuals through automated data feeds instead of waiting on a scheduled cycle. Milestones for 2026 include expanding continuous vetting for non-sensitive public trust positions and beginning Industry RapBack enrollment, which pulls criminal history data in near-real-time for contractor personnel. Full population enrollment in continuous vetting is targeted for September 2028.8Performance.gov. Trusted Workforce 2.0 Quarterly Progress Report – FY2026 Quarter 1
Continuous vetting enrollment records currently sit in DISS, and how those automated data streams will integrate with Scattered Castles over time is still evolving. The direction is not. As feeds expand, adverse information will surface faster, and the comfortable gap between periodic investigations where a financial problem or foreign contact might go unnoticed is closing.