My suggestion is you use the Private Space functionality and install Sandboxed Play along with all your Play Store apps there. And in the owner profile you dont have to have Play Services if you plan to migrate to using mostly FOSS apps that you can get from other sources. You can then share links and files between the apps in Private Space and owner profile, which is a great bonus that boosts usability a lot! From what I understand of your post, your threat modrl probably does not make the setup you describe worth it.
Or maybe even better, keep everything in one profile, and install Sandboxed Play Services along with all your apps. This is the recommended setup for beginners to avoid too much complexity and eventual burn-out and privacy surrender. Remember, having Sandboxed Play Services on GrapheneOS is waaaay better privacy wise than any other OS where those services plus vendor apps are running highly privileged.