I'll just give up. Thanks for your help.
I just found out that you cannot push the datapath (bridge and vlan) from CAPsMAN to CAP but have to place each wifi interface into the bridge on the CAP itself if you use on-cap traffic processing.
What kind of centralised management is this? I mean you can push SSIDs, security settings, channels ... hunky dory. But that's far from managing a fleet of APs. Especially when compared with that other network vendor and their controller. You define VLANs and SSIDs on the controller then push to an arbitrary number of APs.
Time to look into dedicated Router OS management tools I guess. Mikrotik is in dire need of a centralised management platform, IMHO. Yes, Cisco IOS doesn't have that, either, but IOS has more or less feature complete Ansible, for example. The Mikrotik Ansible module has no knowledge of interfaces, bridges, IP addresses, ... it's just an Ansible compatible remote execution tool, so you can pipe Router OS config commands into the device.
Kind regards,
Patrick
P.S. No, I am not just switching to "that other vendor", because they have far more severe technical problems in my experience. It's only their management plane that I envy.