Maybe I don't understand this fully but why not use standard user rights and/or audit?