@yacud i'll whip up a test!!!!
so... it's not as simple as I thought; I got ahead of myself.
according to:
http://www.squidworks.net/2012/08/pfsense-2-0-limiting-users-upload-and-download-speeds-by-limiting-bandwidth/
Setting the mask field to "source address" results in a unique 3x1 queue per source address (later applied in the firewall filter). Leaving that field "none" would result in a single queue that would allow a single user to abuse/hog the full bandwidth availability (3x1).
if your intent is to limit each device on the ap to 3x1 you can work out a schema to ensure those hosts end up with DHCP leases that would match the limiting firewall rule's range of IPs. Or, give them static IPs and add them to an alias.