edent
It requires a lot more "active management".
I would rather say, you can do a lot more active management if you want to or have to (because of your threat model).
But you can also just install GrapheneOS using Web Installer, set up Sandboxed Google Play, and use everything with the default settings, and you'll have a very secure and privacy-friendly device out of the box without much hassle. (Anecdotally: I recently "helped" a friend install GrapheneOS (my help consisted of standing next to him, having a coffee and watching): In less than 30 minutes (and we didn't rush), he had a freshly set up device up and running with all the apps he wanted from Play Store). The only thing he really messed up: He had forgotten to bring a USB cable.)
Things like storage scopes etc are complicated to get your head around. Of course, that's one of the reasons people choose Graphene.
In my opinion (I'm not a techie), storage and contact scopes are fairly easy to understand (not in technical depth, but how they work and what result to expect):
https://grapheneos.org/usage#storage-access
(This is followed by specific information on storage scopes. I think both entries are worth reading in this context.)
https://grapheneos.org/usage#contact-scopes