I do this on my work network: pfsense SG-8860, a combination of Netgear and Cisco managed switches, and finally 6 UniFi AP's and 1 onsite UniFi controller.
The network is setup with 2 networks - LAN and GUEST. The AP's are setup to run 1 VLAN, the GUEST VLAN. The LAN network is also on these access points, but not VLAN'ed. Both of these networks run on the same physical port on pfsense. It took some reading and research, but I got it all working just fine. Firewall rules keep both of these networks from talking to each other.
If you want to do something similar, and from reading your post it looks like you are pretty close, you're gonna need a smart/managed switch. Some 5 to 8 port switch models run about $40 to $45 USD, check out Amazon. The OPT network that runs over to the tenant's apartment is fine on it's own pfsense port, run it directly into there and give it the proper settings. It doesn't need to go thru any of your switches. The other stuff that's "in your own place" should run thru the smart/managed switch, then into a single pfsense port, with VLAN's.
Jeff