My limited understanding of how this works from reading descriptions by others is any registered organizational entity can apply to the CCP for an organization-wide VPN for approved purposes. But the CCP maintains the right to MITM the VPN and snoop your traffic to their hearts' content. I don't see how they can inspect your traffic in the clear though, without coercing you to install their VPN software in order to use a VPN appliance they supply/approve to forcibly modify your browser to accept their certificates, so I'm confused on just how much they can snoop.
So how do these "approved VPN's" really work?