This is exactly what my company went through just a few months ago when we hired an IT security guy whose first order of business was setting up a Palo Alto Networks firewall. Before turning on the MITM functionality he gave a presentation to everyone about what it did, and nobody (support staff, developers, administrators, management...nobody) seemed to mind except for me.
This was what I sent to the HR lead immediately after the meeting:
I remember a while back we all signed some document regarding data security here. I don't remember what that document said specifically -- did it mention at all the possibility that all of our network traffic could be monitored? I ask because, while [new security guy] claims that with the new firewall "No data is stored or made available for other purposes," the fact is that it absolutely can be viewed and stored, and we as the end users have no way to verify whether it is or not. On Palo Alto Network's own website there are comments from other users of our firewall asking how to disable packet inspection in the logs because, "I can also see users passwords in some cases".
I understand and agree with the necessity of setting up a firewall that can inspect encrypted traffic. However, I also understand that this means everything we do or send on the office internet can be inspected by presumably anyone with access to the firewall's back end (including personal passwords and anything usually thought of as "secure"). I'm not sure how clear this is to some (or most) of the employees here. If the agreements that we signed don't reflect this, I think they should be updated and re-agreed to.
[some back and forth ensued, where she reminded me of a line in the agreement that does say we can be monitored at any time]
That may be fine then. All I know is that I heard some concern over being able to go to facebook and whatnot, which seemed to be relieved when we were told it would still work. I just don't know whether or not people realize that while they can still go to facebook, theoretically anything they say or do on it, including all of their login information, chats, and posts marked to be shown only to friends can (though not necessarily will) be viewed by the company as well.
I could be making a bigger deal out of this than it needs to be, I just tend to take online privacy matters pretty seriously. Assurances that the data will be treated responsibly (not viewed or cached) are all well and good, but at least for me, aren't good enough. I won't be going to any personal websites on the network here at all.