You can run profiler to capture usage, analyze, etc. PIA if you ask me. The best and easiest way is to deny login for those you're not sure about and see what breaks or who calls. Then enable them selectively as needed, a few months after that, delete them. I'd use sp_help_revlogin from MS to script them out first in case you need to bring them back. Also script out their roles/permissions.