Ok, fair point. However, I would consider any MDM-enabled device fully "compromised" in the sense that the org can see and modify everything I do on it.
If anything, one of many MDM purposes is to prevent orgas from enrolling rooted devices in their fleet.