Is the SHA256 the secret exponent, or is it taken to the power of a very large unknown number?
It doesn't matter that much, because if there are two people and they want to make a shared address, then it could be 2-of-2 multisig, 1-of-2 multisig or 0-of-2 multisig. Each of that three cases could be handled by Taproot.
2-of-2 multisig: PTLC as it will be in the Lightning Network.
1-of-2 multisig: Spend by key for the more likely path and spend by TapScript for the less likely. Or spend by single key with some commitment (that could be hidden in a signature), just to know who moved the coins.
0-of-2 multisig: No keys, so just a commitment that anyone can produce (and even attach to someone else, just to reduce costs).