Glossary
System Integrity Protection (SIP)
System Integrity Protection (SIP) blocks live access to the system knowledgeC.db and /private/var/db/biome, even as root. Why an image beats disabling it.
System Integrity Protection (SIP) is a macOS security mechanism that restricts access to protected system locations, even for the root user. It is why the system knowledgeC.db at /private/var/db/CoreDuet/Knowledge/knowledgeC.db and the system Biome store at /private/var/db/biome/ cannot be collected from a running Mac with ordinary tools: UAC documents collecting them only when SIP is disabled. Full Disk Access covers user data, not these paths.
Disabling SIP to collect them changes the security configuration of the very system you are examining, which is hard to defend in a report. Prefer a full disk or Data volume image and extract /private/var/db/CoreDuet/Knowledge/ and /private/var/db/biome/ from it on the examination machine, where the suspect Mac's SIP no longer applies. Collect the -wal and -shm files with the database. See where knowledgeC.db and Biome live and how to collect them.