operation-casserole
How you set up your profiles depends on many factors.
For example, the lack of access to certain settings from a secondary profile can be seen as an advantage (security) or a disadvantage (convenience).
Due to the brevity of your description, it is not entirely clear what you want to achieve and why. As described above, an additional gain in security often goes hand in hand with a loss of convenience. Ultimately, you have to decide for yourself what is necessary and acceptable for you.
If you haven't worked with profiles before and your threat model doesn't require it, my recommendation would be to start with a more relaxed approach- at the end of the day, using your device should still be fun.
So you could start by using the Owner Profile with sandboxed Google Play as your daily driver. If you then realize that you can't cope with a setup, you can simply adapt - the nice thing about (secondary) profiles is that you can easily delete them and set them up again.
By the way, profile setup is a frequently discussed topic here in the forum; perhaps you will find some inspiration:
https://discuss.grapheneos.org/d/3677-share-your-graphene-os-setup-here-is-mine
https://discuss.grapheneos.org/d/11715-multiple-user-setup
When reading the posts, you will notice that many users - myself included - have adapted and changed their strategy and setup over the course of time.