I know they are used primarily for detection, but why not go the extra step and make a honeypot that is a truly believable facsimile of a real corporate environment so the attacker wants to stay around even longer. There are lots of clever ways you can switch network traffic to make it look like you are talking to one host when in reality you are talking to a VM jail under a security administrator's desk. Load these environments up with fake, but believable data. How would an attacker know if they are in production actual, or fake prod? Once you "acquire" an attacker, you could even monitor their approach and string them along with hopes of getting into SVRSQLPROD (which is obviously going to be loaded with fake bullshit, but they wont know until they find the symmetric encryption key which you will probably never give them).
Again, I think we are all clear that the above is not deterministic security and that certain experienced attackers (or insiders) may be able to smell such a honeypot from a mile away.