You protect the owner by setting a hard password and disabling fingeprint unlock. Also, if user-profile gets compromised, it won't allow to take over the whole phone - not that this changes much, but ok. I'm assuming this is what graphy00 means.
Not being able to turn hotspot on and off is an old and unnecessary issue on Android side. They just don't bother to fix it as not enough people use phone outside of the owner profile.
@Dumdum Airplane mode, wifi on/off are network features as well, and user-profile can control them. In practice, user-profile can disable hotspot by turning wifi off then on. I'm fine with hotspot config being left to owner, but on/off toggle should be allowed for everyone.
I think this is an upstream issue, not GrapheneOS, but I still have more hope GrapheneOS will be so kind to fix it some day, especially because they recommend usage of secondary profiles. Maybe GrapheneOS could make a found raiser for this fix? I'd contribute right away.