Insider threats remain difficult to identify because authorised users can create security risks through intentional misuse, negligence, or routine errors that resemble legitimate activity. Existing detection approaches mainly rely on technical logs and may overlook behavioural and organisational warning signs, particularly in public institutions with limited monitoring infrastructure. This study developed and evaluated an XGBoost-based model for predicting Low-, Medium-, and High-risk insider threat levels using primary human-factor data from the Tanzania Airports Authority. A quantitative survey collected 2,000 complete responses from employees at Julius Nyerere International Airport, Kilimanjaro International Airport, and Mwanza Airport. Security Awareness, Security Training Effectiveness, Policy Compliance, and Employee Motivation were used as predictors, while Security Risk Behaviour was used to construct the target risk classes. The questionnaire demonstrated acceptable construct-level reliability, and the Kaiser-Meyer-Olkin value of 0.924 indicated excellent sampling adequacy. After data cleaning, reverse coding, composite-score construction, and an 80:20 stratified split, XGBoost, Random Forest, and Support Vector Machine models were tuned using stratified five-fold cross-validation. XGBoost achieved the strongest test performance, with 83.50% accuracy, 83.55% macro precision, 83.23% macro recall, 83.37% macro F1-score, and a direct multiclass ROC-AUC of 0.9389. Policy Compliance was the most influential predictor at 38.40%, followed by Security Training Effectiveness at 31.65%. The Medium-risk class produced the greatest classification difficulty, whereas no model directly confused Low-risk cases with High-risk cases. The findings demonstrate that structured human-factor assessments can complement technical controls and support proactive, ethically governed insider-threat risk management in Tanzanian public institutions. The results provide context-specific evidence for resource-constrained public-sector cybersecurity decision support.