Clients with certs assert their name to servers, and if the server trusts the cert issuer then it accepts the name that the client asserted.
Yes, precisely. So when you compare that name with that of your known clients, you can be confident you are not being duped.