To manage application logs securely for a company, which are backed up to a Cloud Storage bucket shared with analysts and administrators, where analysts should only access logs devoid of personally identifiable information (PII) and PII-containing logs should be stored in a separate bucket accessible only by the administrator, what action should be taken?