Ah! You are confusing Clearpass roles with the controller roles.
A role in clearpass is like an internal derivation which then can be used for an action.
Look at Enforcement Profles, here you create an "action" which is the Aruba-User-Role RADIUS VSA. Add a new enforcement profile and there should be an option for Aruba Role. Then, you can name it to match what's on the controller.
The Clearpass role is used as a condition to send this action. Look at the enforcement policy. All this really is are "IF THEN" statements.
IF the conditions on the left are met, send the action(s) on the right. The actions are enforcement profiles. These conditions are things like the roles you created or any other variables you see listed when you go ahead and create an enforcement policy...
To leverage those roles, the call up for them in the enforcement policy is "TIPS:ROLE EQUALS <value>" TIPS is the call out for clearpass roles