They give clients "permission" to access servers. If a client accesses a server and there's no CAL for that client, you're in violation of your licensing agreement. They're kept on paper basically.
The planned product will technically function as a thin client that access the Windows server terminal services over Microsoft's own remote desktop protocol (RDP) and Citrix's ICA protocol but also ...