A legal firm is using a foundation model on Amazon Bedrock in a Retrieval Augmented Generation (RAG) setup to analyze contracts stored in Amazon S3. Each department works with different clients and must not access other clients’ contract data. How should the firm manage access control to uphold data security?