You are designing a data security strategy for a BigQuery dataset that contains sensitive financial information. To comply with internal policies, you need to ensure that only authorized users can decrypt specific columns containing sensitive financial transactions, while allowing analysts to query the data in an encrypted state. Which approach should you take?