Hat I tend to follow the team's recommendations when I see them, but I also tend to keep the default settings, especially since resetting the settings is not possible.
You can change any of the settings in Settings > Security & privacy > Exploit protection at any time. There's no harm in enabling them at all – you can read the subtext under each setting for more info. These settings can be reset easily even per-app.
Hat Another recommendation from the forum that could be included is shutting down the private DNS when using a VPN.
This is already noted here (actually in bold text): https://grapheneos.org/faq#vpn-support
Hat It would be helpful to have a page on the site with basic but important setting recommendations.
I'm not so sure. I think the default settings already provide a good balance between security/privacy and usability for most users. I think "recommended" settings will vary according to each person's needs / threat model – perhaps it's slightly out of scope for the project to delineate which settings they would recommend for specific groups of people / threat models (would take time). Most settings are explained on the website and users can decide which ones they want to enable.
Perhaps community members want to make guides / recommended settings lists for specific threat models. For instance I vaguely recall someone sharing a recommendation guide for anarchists. Some users might actually be better placed to make recommendations than the project, such as protestors with experience of risk during active protests (experiential insight).