the secure.log includes logs of computers that remote into the computer VIA ARDAgent. This includes the time date, account, and IP address of a computer they used to remote into the computer. The secure log is found in /var/logs/secure.log.
If they're using some thing other then the built-in remote fetures of the mac. Then your not going to see any thing in the secure log.
of corse you could just have all the passwords updated on the mac. Make sure ARDAgent is restricted. So they hopefully can't remote into the computer.
Also keep in mind an IP address has limitations. IE if I remote into a computer on 1/2/12 and then you check the log on 4/2/12, by that time some one else may have that IP address.