I think you either misread, or I was unclear -- we're in agreement.
Company network with company devices: sniffing traffic is fine, insofar as it's done by configuring the devices with a private CA.
Company network with personal devices (including visitor's devices): silently MITMing SSL using forged certificates and a real CA is not fine. They can either forbid the use of personal devices, or request that I install their internal CA.
Company network with company devices: sniffing traffic is fine, insofar as it's done by configuring the devices with a private CA.
Company network with personal devices (including visitor's devices): silently MITMing SSL using forged certificates and a real CA is not fine. They can either forbid the use of personal devices, or request that I install their internal CA.