Perhaps GrapheneOS should just be an ASOP release with implicit security features that makes it hard to notice it is anything different. If people think it is a vanilla Android install, it would give them no reason to imply criminal activity.
Google is never going to put their administrative access in a restricted sandbox.
That is diametrically opposed to their interests in data collection.
Not worthwhile or feasible. The OS is not designed to hide its identity.