We don't make features designed to trick people with no technical skills because people who were compromised ALWAYS underestimated the capability of the threat that targeted them. You shouldn't rely on slight of hand or pretty tricks, you should just have *more security*. GrapheneOS is becoming far more popular and recognizable so you can't guarantee you will be trusted that your 'decoy' is legitimate to someone.
All enforcement agents use widespread commercially available forensic extraction tools. You don't need to be smart to use it. Please Google screenshots of Cellebrite UFED, a child could navigate it, it is that simple. It doesn't need a special device and you can run it on a laptop.
It uses ADB to perform extraction and a secondary user does not have access to configure the features. There is zero deniability designed with the user profile approach and that's why it wouldn't be considered with many implementations people make up. Owner also hosts critical OS functions, so it cannot be wiped. It would require a massive redesign on how the OS users and filesystem encryption is laid out.
Virtualization is the way to go for something like this.
