data-engineer video for a marketing agency frequently runs ad-hoc queries on datasets stored in Amazon S3 using Amazon Athena. They need to establish strict
A marketing agency frequently runs ad-hoc queries on datasets stored in Amazon S3 using Amazon Athena. They need to establish strict access control measures to ensure that different departments within the agency can only view and run queries relevant to their specific projects and cannot access others' query logs or results. What approach should the agency adopt to enforce these fine-grained permission controls within their shared AWS account?