What compromise are you doing with GrapheneOS+Google services that you aren’t making with microG? In my experience the sandboxed version of Play Services works much better than MicroG, with the added security of using an android native service developed by Google themselves.
You can argue “MicroG isn’t Google” but it actually is since it’s just a bunch of Google libraries with some FOSS costing on top. And again, you’re more likely to get your phone remotely hacked by a silly exploit that was patched months ago but still got you because instead of GrapheneOS you decided to use some other security-void like Calyx, LineageOS or /e/OS.