The posts by Michael and Darrel are exactly right. You might want to consider using role based access to consolidate users requiring different policies into a single SSID for each method of authentication (combine the psk networks together, combine the 802.1x networks together). If you're not using radius, you can use DPSK to map users to different roles. Each role can specify the ACL, vlan, operating schedule, rate limits, OS policies, and application policies. You can control just about everything with role based access.