In an ideal world, someone could maintain the canonical best practice setup for say a locked-down desktop lab, and everyone else just clicks/types "install me a locked down desktop lab system," applies any site-local tweaks, and that's it.
Do things like LCFG http://www.lcfg.org/ help?
inv.sno <snip> inv.allocated cedward1 inv.location JCMB-<snip> inv.manager cedward1