In case of client credentials grant in the authorized access use case, a client application impersonates a user that has authorized access to 1-to-n server applications. See also Client Credentials Grant - SSO.
Impersonation is configured as a specific link between the application and the user.
NOTE that if an application impersonates a user which is deleted from the system also the link will be removed. A new user must be linked to the application to make client credentials grant authorized access use case functional again.
...