Normal usage would require a reauthentication - i.e. FaceId or TouchId - to produce the passkey.
I think the more general point is that "able to unlock the phone" is not / should not be the same as "I have verified that this is you" for sensitive applications and information.
Of course, if you've enrolled your kid's fingerprints they'd have access.
> you will simply unlock your phone
Then I guess that really is no different from opening an app.