The format and location of the TCC database is not considered API, so it’s not something I’ve spent a lot of time looking at
Suppose you have a security product doing a scan of your computer and upon initiation of that scan, contents of $HOME is enumerated and user is spammed with every TCC access dialogue in the book (Downloads, Contacts, ...). Yes please, give us an API to do this transparently so that we don't have to access SIP protected files in order to gain FDA and forego the rest.