Hello Lukas,
Integration of PAM SC with PAM basically propagates the user logged on to the PAM portal into session of the PAM SC endpoint.
E.g.
1. logon as "super" to the PAM Client
2. then open an SSH access session from PAM to the PAM SC endpoint
3. in the session submit "sewhoami" and observe it returns "super"
This means any authorization to resources protected by PAM SC on that box apply to "super"
To answer your question, yes, the authorization to the PAM SC resource is specific to the user logged on to PAM itself (1.) – not to the account used to open the session (2.)
Best Regards,
Andreas