You're correct about always having to evaluate security in terms of threat models, but you're off about a lot of your examples.
>Close person tries to get in (significant other, coworker, ...): biometrics is flawed, password works.
>Government respecting your rights tries to get in: biometrics is completly broken, password works.
The first is fully incorrect, the second far too generalized and heavily incorrect. PINs/passwords are far, FAR more trivial to skim then biometrics. Even mere shoulder surfing isn't hard, but in a world with approaching ubiquitous hard to notice downward looking cameras if you ever input a password anywhere that isn't physically secure, and with no one looking, you can easily have it compromised. And it of course takes essentially zero resource expenditure and offers zero visibility to merely use the password once it's acquired.
If it's at a random incident and a first-world type government wants to look, you can trivially disable biometrics on any decent implementation without even looking. So lack of biometrics buys you nothing. If it's a sting against you specifically then they can shoulder surf/camera it (remember the constant improvements in drones, are you REALLY not being watched well away from buildings even?) or just wait for you to unlock it and then swoop in and try to physically grab you while it's unlocked anyway. The scenario space where it'd make a difference is very, very minimal. Really, you want both: a strong password and biometrics for public usage. And for scenarios like border searches they can lawfully cause you enough inconvenience regardless that standard passcode is still not really the right response anyway. A burner, clean+remote load later, or alt-codes or the like would be the right way to go, though sadly I think only the first two are available right now.
>Government that don't respect your rights tries to get in: https://xkcd.com/538/
Possibly the dumbest xkcd ever made.