I actually work for a company that sells a SIEM tool that lends itself very nicely to monitoring of insiders. (read: employee surveillance) While most usecases are around PCI-DSS, HIPAA, and that sort of thing, invariably there are "four eyes" usecases as well. These usecases tend to bridge into the way an employee compares to their fellow employees, particularly those in the same business unit / group / job function. This tends to uncover things like people in x group come into work at 9:01a, Bill, a member of x group, comes in at 9:33a most days. Bill also tends to browse the internet on y-type sites whereas people in x group are usually active on z-type sites. Bill spends b-time with the average customer call, and takes c calls per day. Whereas x-group employees typically take 10minutes less than b-time for the average customer call, and take c+5 calls per day. SIEM tools are built to bring in most any type of data, and lots of it. Built-in correlation is normally security-centric, but is easily adapted for most anything. For example, Bill is marked as being on a business trip to Birmingham, AL but his VPN connection is coming from the FL keys *flag*. Or, more ominous, Bill said he was out at lunch with clients for an hour, but the geolocation-software installed into his phone says he was located around a car dealership, and was there for 3 hours.