It should be enough to add the team identifier in Kernel Extension Policy MDM payload settings for Apple devices
User Approved Kernel Extension Loading (MDM Deployments)
See Kernel Extension Policy MDM payload settings for Apple devices
https://support.apple.com/en-gb/guide/mdm/mdm88f99b98a/1/web/1.0
Developer ID Application: Check Point Software Technologies (TZ3UEPFYKD)
Full Disk Access Requirements
See Custom MDM payload settings for Apple devices https://support.apple.com/en-gb/guide/mdm/mdm38df53c2a/1/web/1.0
Agents requiring Full Disk Access
/Library/Application Support/Checkpoint/Capsule Docs/CapsuleDocsAgent.app/Contents/MacOS/CapsuleDocsAgent
Daemons requiring Full Disk Access
/Library/Application Support/Checkpoint/Capsule Docs/CapsuleDocsDaemon
/Library/Application Support/Checkpoint/Threat Emulation/cpted
/Library/Application Support/Checkpoint/Anti Ransomware/cpard
/Library/Application Support/Checkpoint/Forensics/cpefrd
/Library/Application Support/Checkpoint/Endpoint Security/cpmed
/Library/Application Support/Checkpoint/Endpoint Security/cpamd
/Applications/Check Point/cpmedApp.app
/Applications/Check Point/cpamdApp.app
/Applications/Check Point/cpdaApp.app
/Applications/Check Point/efr-mon-epsec.app