the main difference between AD and local (users or groups) is that local only exist in the computer they have been created. AD users or group exist all over the domain and can be referenced in all the computers that belong to that AD.
Local or AD users can have different profiles / permissions depending on the role ("normal" users, the lowest level; "pwer user", a step beyond with more permissions; or administrators that have full control). These profiles apply only to users, not to groups.
Regarding Qlikview, I have always used AD users to grant the permissions to the documents.