The MR access points have an in-built firewall, so the easiest way is to make sure that on the firewall for the “guest” SSID rules you have a rule that blocks traffic to all your corporate IP addresses.
From memory the default configuration for the SSID firewall is to deny all traffic to the private IP address spaces (I.e. 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), so if your corporate network is in this address space it’s likely the default settings will prevent the “guest” SSID connecting to the corporate network (and hence why all the documents describe enabling it).
EDIT: Just checked a few and the default rule seems to be to “Allow” Any to the Local LAN. Just swap this to Deny Any to Local LAN and this should be what you need for the “guest” SSID. (Local LAN is the private address space).