So I moved to Dhizuku. It's a bit hard to setup, but once I'm done it's felt like untethered jailbreak - I don't have to complicated dance to start Shizuku now. Dhizuku basically make your phone a company phone, except it report to you. To setup a "managed main profile" you'd need to remove all accounts visible in Android account system and type a long ADB command so I don't think it can be maliciously done.
I suppose this will be how we'll use F-Droid in the next year for enthusiasts.
However, it's problematic if the banking apps also block regular configurations on something like GrapheneOS, e.g. by inspecting the initial call stack of an app. There are many such trivial to bypass ways of doing root detection and most are easily circumvented anyway.