I'm just dipping my toes into multisig.
After reading following article, it was clear to me that if you want proper OpSec, it's nearly impossible to create a decent UX while following all security guidelines for multisig.
The basic starting point to consider, is that every device is compromised.
https://benma.github.io/2020/11/05/multisig-xpubs-verification.html