Eliohann
Good day, excellent choice in GOS.
1) keep esim = Flash GOS and then it's already inside of GOS for you.
2) close. Yes, do the following in the owner profile.
RCS:
- Google play services = phone permission
- Google Messages = default SMS app
- Some carriers might require google to have some direct hardware access for authentication
Settings > Apps > Sandboxed Google Play > Play services special permissions > enable ICC permission
source:
https://grapheneos.org/usage#rcs
3)
a list of tested bank apps on GOS:
https://privsec.dev/posts/android/banking-applications-compatibility-with-grapheneos/
Private space info:
Its settings are in settings > security > private space
I'd set: unlock method = device unlock
This equates to no periodic authentication prompts.
Automatically lock = when device reboots
PS will stay unlocked so you get notifications
Location usage in PS (Private space)
settings > location > enable location use in private space
Extra profiles
Yes, you can have 3. Some people have: Owner + PS + 10 profiles
Settings > system > users > [your 2nd user] > allow running in the background
Should work out all fine but test your Slack notifications--while you're in owner--before you are on-call. If you have any issues, stay in the 2nd profile while on-call until you fix the notification situation.
Luckily, you can customize notifications to have your 2nd user notifications be a unique sound, vibrate, and/or override do-not-disturb (to do this: Hold your finger down on the notification > gear icon)