This can be solved by having a system in place with two passwords and partitions: assuming the phone is already locked, entering the second password unlocks a decoy phone account without anything incriminating, but at the same time encrypts or wipes the actual/main account. Entering first password unlocks the main account. The agent has no way of knowing if the first/second is being used.