You should add a Part 2, 3, 4 with more details. knowledge helps to avoid mistakes and misunderstandings.
Thanks for the details about "EXO has it's own directory" and even the DualWrite and ForwardSyncProcess (which cannot triggered by an admin unfortunately)
Licensing: It would be nice to trigger Power Automate or allow to start an Azere function if changes like "new Mailbox provisioned" happens to trigger followup actions.
About SOA: "on-premises directory will be the SOA (with very few exceptions). " Part 2 should cover these exceptions (i found "RequireSenderAuthenticationEnabled" us one :-/)
HCW should check if the "ADSync Hybrid Checkbox" is really enabled, because some things are working even without that checkbox.
And some words about "EOL GroupsWritebackV2" would be nice.
Looking forward to next parts