Assuming you are using the inbuilt Clearpass roles you just need to create an Enforcement Policy which maps the roles to the Enforcement profiles you create like shown by cjoseph:
Tips Role EQUALS [Guest] RADIUS-Guest_Enforcement_Profile
Tips Role EQUALS [Contractor] RADIUS-Contractor_Enforcement_Profile
This policy should be first match.
As long as the guest account has the correct Clearpass role the correct enforcement profile should trigger and this should set the correct Aruba controller role.