Build Secure Agent-to-App Connections with Cross App Access (XAA)

In the ID-JAG RFC, it is mentioned that the IdP can include the email attribute as a claim. Could you please confirm if this is the expected approach?