Hi Atul,
For status management , the configuration you have done seems to be fine but the above screen shot of pfcg shows that you have one more configuration for generic statuses :
All Activities
*
COH , COI
*
This might be giving all authorizations to all the statuses.
/Hasan