Goal:
Create an IAM role policy that allows the role to perform defined AWS Athena read actions on Athena resources only if the role tag equals the A