Hey John,
All the UTP actions are performed on the AP so that you can enforce consistent policies on both tunneled and non-tunneled WLANs. In role-based policy scenarios, if you are using the SZ to centralize the authentication process (i.e. SZ is AAA/RADIUS/NAS Client), then the role is resolved on the SZ and sent to the AP for policy mapping. Otherwise, the AP does this locally.
thanks,
Marcus