So we got this to work by using the following:
Service-Type=%CUSTOM2% for the custom RADIUS attribute.
The Policy mapping is as follows:
Most of the config work has to be done on the ASA side. I did it using the ASDM. This method allows for RADIUS auth to both the ASMD and SSH. Priv exec mode also works as well. These settings were configured through the ASDM.