at work we use etrust ITM on every work station (about 10,000 computers) and it monitors the systems in the background constantly. On user comptuers we have the etrust gui disabled, so they can't even turn it off.
Our Macintosh Computers don't run anything, just behind a NAT router on the network