One trick I've found, to at least discourage employee use of the Guest SSID: make (true) Guests actually authenticate to access. Then require them to re-auth regularly. Because they'll probably only do it once or maybe twice for a brief visit, it's not too much of an inconvenience to them. But for employees who are there very regularly, it will become a pain and they will most certainly use a different, more appropriate, more friction-free approach if you provide them with one. Something like Trusted Access or maybe iPSK, for examples.