On occasion the sewhoami -a command shows the user as an OS_user or root but does not list the expected AD group names in the Group Name table. When this happens the sesu command fails when attempting to switch to another user account.
PAMSC policies can be applied directly to a user but most often they are applied to a user group. This group can be based on local OS groups or AD groups when an Active Directory integration is implemented in the Linux or Unix OS. The sewhoami command is useful when trying to evaluate why a policy, including sesu policies, is not being allowed. If a user is misidentified or their user groups are not identified properly, the policy cannot be properly applied.
The relationship between sewhoami and the policies that are applied is simply that the sewhoami can show you the details of what PAMSC has identified as the current logged in user. In oder to ensure any policy is applied you can use the sewhoami command to validate and fix any underlying identification issues.