silentmajority
As already suggested, I would go with Main Profile + Private Space.
This is the most fitting for almost everyone, plus it's very user friendly.
Personally I use the Main Profile for FOSS apps only without PlayStore and the Private Space with sandboxed Play Store with those apps that requires Google Services, but this is merely a personal preference.
n3t_admin It might be smarter to use something like Insular for a work profile
While this can work for some users, keep in mind that you will have some downsides, like apps never going "to sleep" and as far as I know you would also miss the new (as in second/another) disk encryption that you would get with the Private Space.