I am using my ISP ONT fibre modem connected to the WAN of the brume 3. From the brume 3 I have 2 switches, both are managed which are VLAN aware, one is a 8 port 2.5gb with 10gbe SFP+ port switch and the other is a 4 port 2.5gbe 2x 10gb SFP+ My switches are connected together with a DAC cable via SFP+
From the there the main 8 port switch is used for local clients (wired) and the PoE switch servers for my Access points. I have two grandstream access points (had unifi but changed to grandstream (GWN access points) and prefer them as I can dedicate the controller on the access point instead of relying on another hardware key or a docker like unifi / omada.
The two access points are connected to trunk ports which have my VLAN IDs tagged directly to the Access points. On the master access point that is set as the controller I make my wireless changes / settings (it then applies to my other access point as it's part of the same controller - adopted) I create my wireless SSIDs along with their password and configs and also tag each SSID on the access point controller with the same VLAN ID I created on the Brume 3 so that they match. Now if say a guest connects to the guest SSID with VLAN20 for example they will then go to the brume 3 VLAN20 DHCP etc.
I use dedicated access points like the grandstream because they connect via PoE which means I can place them anywhere without the need of a traditional power supply, up high, centrally where a traditional power cable couldn't reach. Because they are PoE it serves as both the power and the ethernet connection back to the switch.
You can look here for a script that will help with your VLAN creations.
There is also this guide which is more manual
Maybe you have a hub and a light for example.
To be honest I keep thinking of just going back to a flat network, no VLANs due to the hassle (hence hoping newer firmware is more accessible for VLAN and interface creation) of setting up every time there's a new firmware etc and the fact I don't really have anything IoT related or even many guests that wish to connect to my WiFi lol. One reason I keep doing it is mainly to learn but also I do self host things so I dont want certain things visible to guest if they ever stumble across things.