You should make a trunk to the access point.
Create sub interfaces on the ethernet and dot11 radio of the ap.
give all the sub interfaces their separate bridge group id.
create the ssid's with the dot11 [ssid] command and assosiate them with the appropriate vlan.
configure the encryption in one of them.
only set the ssid guest mode to the visible vlan.
Good luck