WSUS uses the Automatic Update client on the workstation to run the updates in the context of the machine. If the workstations are reporting to WSUS properly, then every 22 hours +/- they will check for updates, download them locally and run them at the time you set to be run.
There really is no need for the user to be involved in the process at all. They do not see the update shield in the tray like an Admin does but this doesn't affect the fact that they patch.
You can set via GPO the ability for non-admins to see the shield if you want, but it's really quite pointless - the machines will patch on schedule.