Hi,
You could use the radius attribute "Cisco-VPN3000:CVPN3000/ASA/PIX7x-Tunnel-Group-Name CONTAINS <TUNNEL NAME>" inconjunction with the AD group to authenticate the users to the different tunnel groups (aka connection profiles). In your example you'd create 3 rules, 1 for each tunnel-group/connection profile.
Here is an example, although it's for ISE, it is the same principle.
HTH