Seems like you intercept the request and use an admin service account token then impersonate?
Infra runs a lightweight process in-cluster that intercepts requests and verifies them - and yes, this process intercepts requests and then impersonates the correct users and groups.