You would define a Bandwidth profile Globally in the VNS area (you can define multiple) and then you would create a Class of Service (CoS) that applies the Bandwidth profile you desire for either outbound traffic or inbound, or both. That resultant CoS can be applied to a WLAN service as a whole, or it can be applied to a specific Role ... that you could assign to a specific user or groups of users via RADIUS in the form of a Filter-ID passed back to the controller upon successful authentication for the client.
Additionally, you can apply any CoS (and and bandwidth limiting that has been defined in it) to any individual Policy Rule that is defined for any given Role.
The bandwidth limiting will apply to each individual user in any of the above cases ... and not per WLAN or SSID.
Hope this helps.