Compose new identities on one authored screen. master
PERSONAS interleaved creation with its roster: every protocol group ended in its own ADD NEW {TYPE} PERSONA row, so the protocol choice was made three times over at three places in the list, and the identity that came out was named by serial. The rail now lists every owned identity first, still grouped by protocol in the fixed Research / Operations / Security order, and closes with one ESTABLISH NEW IDENTITY row. Entering that row opens an identity-creation screen on the origin picker's grammar: all three protocols at once with exactly one current, the current one carrying its consequence read, then the name, ESTABLISH, and CANCEL. Names became authored input — CreatePersona carries an optional name and Sim::suggested_persona_name draws deterministic suggestions from sim state and a reroll step, never the wall clock, skipping a name an existing instance already wears. The screen is frontend attention state beside `confirm`, and it renders as an ordinary object plus ordinary action rows, so terminal and Bevy print it through the detail pane they already had. Agent mode skips it entirely: the creation row carries one bound row per protocol under `persona new`. Fixing the draft's detail pane exposed that Bevy read the object rail by index instead of asking the workspace what was selected; it now asks, as the terminal already did. Defense: implements operations-workspace.md's amended PERSONAS section and its new "identity-creation screen" clause — the roster reads before the door, the protocol comparison is one decision carrying its consequence read, ESTABLISH dispatches the exact projected CreatePersona row rather than a second execution model, and confirmation still follows consequence so a free unsigned creation does not ask twice. Amends personas.md for authored names and the retired serial defaults. ActionCommand is not persisted, so the save format is unchanged.