AnaNg
That said, how easy is it to screw up a phone when installing an OS?
Web installer makes it super easy, it can break, but hardly to a point where its a brick, unlike the old days of rooting phones, I believe a lot of the web installer is the same as Googles official one?
Does ROM=Phone OS?
ROM isn't really the correct term, however you are correct, GrapheneOS is an Operating system based on Android (it flashes all the internals also)
Can I order a phone per-configured with GOS from a trustworthy source?
Just buy it from a local shop if you can, Nitro do sell pre-built GOS phones, at a significant cost
For authentication apps like Authy, is it simple reinstall process to the new phone?
You have multiple options, Fdroid (Droidify, Neo Store ideally), Sandboxed Play Services or Obtanium can all get Aegis, obviously you need to export the existing vault (.json format), but otherwise it works exactly the same
Just to add, misread the above, for Play store based apps you can use Sandboxed play store, Aurora Store, or as a last resort APKMirror
-Is there an app similar to google keep notes for GOS?
Not natively installed, think as GOS as a base, then you configure how you need, use F-Droids webpage to get an idea, then go from there, I believe BeauTyXT maybe something that fits your needs?