I would go one step further than @DarrenOC
Either move to 802.1X or, if you want to keep PSKs, push the passphrase to the clients with an MDM. That way the users can not read the password.
In addition to that, allow the users to connect their personal devices with a different SSID/profile with reduced connectivity to your internal network.