Figured it out. I think I had a typo...anyway, here's what's needed:
in the sudoers file:
Cmnd_Alias ANSIBLECMNDS=/usr/bin/ansible, \
/usr/bin/ansible-console, \
/usr/bin/ansible-doc, \
/usr/bin/ansible-galaxy, \
/usr/bin/ansible-playbook, \
/usr/bin/ansible-pull, \
/usr/bin/ansible-vault
User_Alias IDMADMINS=%ansible-admins-group-name
Runas_Alias ANSIBLE=ansibleuser
ANSIBLEADMINS ALL = (ANSIBLE) NOPASSWD: ANSIBLECMNDS
in the .bashrc or .bash_profile or .bash_aliases or profile.local or whatever you use:
alias ansible='sudo -u ansibleuser /usr/bin/ansible'
alias ansible-console='sudo -u ansibleuser /usr/bin/ansible-console'
alias ansible-doc='sudo -u ansibleuser /usr/bin/ansible-doc'
alias ansible-galaxy='sudo -u ansibleuser /usr/bin/ansible-galaxy'
alias ansible-playbook='sudo -u ansibleuser /usr/bin/ansible-playbook'
alias ansible-pull='sudo -u ansibleuser /usr/bin/ansible-pull'
alias ansible-vault='sudo -u iansibleuser /usr/bin/ansible-vault'