Two phones (business and private).
Business: Everything simple, only owner profile, real Google account, all necessary apps. This way I know it works and I still get the enhanced security, sandboxing and permission management of GOS.
Private: 4 Profiles
- Owner: Exclusively for system settings and installing/updating apps (which are otherwise disabled) through throwaway Play Store account and Obtainium
- Main: No Sandboxed Play, all apps I use often and can't just use the website in Vanadium for.
- Rare: No Sandboxed Play, apps I occasionally use
- Offline: No Sandboxed Play, only for files I need offline. WiFi is disconnected before switching to this user.
This is my best solution to balance my threat model needs with some convenience.