AWS MSP VCL 8.0
The AWS MSP Program Validation Checklist (VCL) 8.0 becomes the only accepted checklist for AWS MSP Partner (re)validation on 1 January 2027; VCL 7.1 sunsets on 31 December 2026. Version 8.0 has 61 controls, 24 new and 27 rewritten, and shifts the emphasis to demonstrable AI delivery: observability of GenAI/agentic workloads, toil measurement, AI governance and AI dependencies in vulnerability management.
monsys measures the technical controls on that list and bundles the evidence in an Ed25519-signed evidence pack. The declarative controls (policy, roadmap, practice lead) are attested by the MSP on the last page of that pack.
Dashboard page
Section titled “Dashboard page”Sidebar → Security & compliance → AWS MSP VCL 8.0 (/compliance/VCL8).
Above the generic control table sit three KPI blocks:
| Block | Controls | Source |
|---|---|---|
| GenAI & agentic AI observability | OPS-004, OPS-009, GOV-002, GOV-003 | ai_apps, ai_traces, ai_agent_sessions |
| Toil measurement & reduction | OPSP-003 | toil_metrics |
| Vulnerability, change & access management | SEC-003, GOVP-001, SEC-001, SECP-001 | inventory_dependency_cves, os_package_cves, emergency_tokens, users, agent_certificates |
Below that is the control table as for NIS2/CRA/ISO 27001: id, description (NL/FR/EN), coverage level, evidence count and review status.
What monsys measures per control
Section titled “What monsys measures per control”| Control | What VCL 8.0 asks | monsys evidence | Level |
|---|---|---|---|
| OPS-004 GenAI & agentic AI observability | agent session tracing, inference performance, drift, decision audit trail, cost | ai_traces + ai_spans (tokens, latency, model, refusal, PII hits), ai_agent_sessions (per session hash), ai_alerts (drift/cost rules) |
automatic |
| OPS-009 FinOps incl. AI cost | inference cost per app/model | total_cost_micro_eur per trace, pricing snapshot |
automatic |
| OPSP-003 Toil measurement | toil as % of ops time, quarterly reduction | toil_metrics: automation ratio, auto-resolved alerts, MTTA/MTTR per month + quarter delta |
automatic |
| SEC-003 Vulnerability mgmt incl. AI deps | scan AI model/agent dependencies | OSV/EPSS/KEV on app dependencies (pypi/npm/Go), OS packages, kernel, images | automatic |
| OPS-010 Patch & release | documented patch execution | remediation_latency per host, signed result |
automatic |
| GOV-003 Data governance for AI | PII protection | redaction level per AI app, PII redaction at source | automatic |
| GOVP-001 Change management incl. AI workloads | approved, traceable changes | Emergency Action Tokens: signed, single-use, with result | partial |
| SEC-007 Agentic zero trust & blast radius | containment of agent actions | per-host exposure (centrality, internet-facing), single-use tokens with action list | partial |
| SECP-001 Encryption & key management | mTLS with per-agent certificates, Ed25519-signed evidence | partial | |
| SEC-001 IAM | scoped roles, TOTP, access-review report | partial | |
| SECP-004 Prompt injection prevention | guardrails on AI endpoints | refusal and anomaly detection via ai_alerts; guardrails themselves are app-side |
partial |
| GOV-002 AI agent & model governance | inventory with owner and risk tier | ai_apps with owner_email, declared_risk_tier, declared_models |
partial |
| PLAT-004 Agentic AI platform | human approval before every action (EAT + TOTP), never autonomous LLM execution | partial | |
| PLAT-005 Well-Architected | Trust Score per tenant | partial | |
| GOVP-002, BUS-002, BUS-006, PEO-003, PEO-004 | policy, roadmap, specialisation, people | attestation checklist in the evidence pack | manual |
Toil metric (OPSP-003)
Section titled “Toil metric (OPSP-003)”ToilMetricsWorker recomputes daily, per tenant per calendar month:
total_actions— executed Emergency Action Tokensautomated_actions— tokens issued by a monsys worker (reasonstarts withauto-: auto-patch, auto-update-all)manual_actions— tokens issued by a personautomation_pct—automated / total × 100total_alerts,auto_resolved_alerts(resolution_notes LIKE 'auto:%')mtta_seconds,mttr_seconds
The quarter delta compares the mean automation_pct of the last three
months with the three before. Positive = more automation = less toil.
Without two full windows the hub shows n/a — a trend is never invented.
API: GET /api/v1/ops/toil?months=6
Agent sessions (OPS-004)
Section titled “Agent sessions (OPS-004)”AIAgentSessionsWorker rolls up the last 90 days of ai_traces hourly
per (tenant, app, user_session_hash): number of traces and spans, tool
calls, tokens in/out, cost, models used, refusals, errors, PII hits. The
hash is set by the SDK; the hub never sees a raw session id or user
identity.
API: GET /api/v1/ai/agent-sessions?days=30&app_id=&limit=100
Evidence pack
Section titled “Evidence pack”Reports → AWS MSP VCL 8.0 evidence pack (aws_msp_vcl8, tenant scope,
admin). Sections:
- Control coverage (all mapped controls, level, evidence count, review status)
- GenAI & agentic observability per app + session KPIs
- Toil & automation (6 months, quarter delta, method)
- Vulnerability management incl. AI dependencies (per ecosystem/severity, KEV, fix available)
- Change management & blast radius (signed actions auto/manual, failure rate, top-exposure hosts)
- Attestation checklist for the declarative controls, with signature line
The pack is Ed25519-signed and offline-verifiable like every other audit
pack (monsys-verify). Toil and session aggregates are recomputed fresh
before rendering.
What monsys does not do
Section titled “What monsys does not do”- No compliance verdict: monsys supplies measurements, the auditor judges.
- No guardrails inside your AI app: SECP-004 requires input validation on the endpoint itself; monsys detects the consequences (refusals, anomalies).
- No measurement of human hours: toil is a proxy based on automated vs manual actions.
- No roadmap, practice lead or vertical specialisation: you attest those yourself.