## Step 7  -  Platform Identity Routing (optional)

Map repo URL **glob patterns** to a named identity from `prefs.global.identities`. Phase 0 consults this map in Step 5 to auto-pick the git author and the right `servicePatMap` for the target repo  -  preventing corporate identity leakage into personal repos and vice versa.

Auto-skipped if `identities` has fewer than 2 entries (single-identity case has nothing to route).

**9a. Auto-suggest from `servicePatMap` ownership**

For each identity, derive a default routing rule from where its PATs work:
- Identity owns `bitbucket` PAT → propose `<bitbucket-host>/*` glob, mapped to that identity.
- Identity owns `github` PAT → propose `github.com/<gh-username>/*` if known (from `identities[].username`), else `github.com/*`.
- Identity owns `confluence` / `jira` only → no URL routing applies (those aren't repo origins)  -  skip.

Auto-suggestions are **proposals**, not forced. User confirms or edits each one.

**9b. Confirm or edit each suggested rule**

```
Step 7  -  Platform Identity Routing (optional)
Auto-suggested rules:

  1. bitbucket.{corp-domain}/*                  -> corporate    [confirm/edit/skip]
  2. github.com/{personal-username}/*           -> personal     [confirm/edit/skip]
  3. github.com/{org-name}/*                    -> corporate    [confirm/edit/skip]

Add another rule? [Add another / Done]
```

Each rule answer:
- `Enter` or `c` → confirm
- `e` → edit (prompt for new glob and/or new identity name)
- `s` → skip this rule
- `n` (final question) → finish

**9c. Save**

```json
{
  "global": {
    "platformIdentityRouting": {
      "bitbucket.{corp-domain}/*": "corporate",
      "github.com/{personal-username}/*": "personal",
      "github.com/{org-name}/*": "corporate"
    }
  }
}
```

Glob matching semantics (Phase 0 implementation):
- `*` matches any characters except `/`
- `**` matches any characters including `/`
- Most-specific match wins (longer literal prefix > shorter)
- No match → Phase 0 falls back to the interactive identity picker

**9d. Skip / degrade rules**

- Zero rules saved is valid  -  Phase 0 always falls back to the identity picker.
- A rule may point to an identity name that doesn't (yet) exist in `identities`; on Phase 0 lookup, an unknown identity name surfaces as a warning and the picker is shown.
- Step 7 is idempotent  -  re-running merges new rules; existing rules are preserved unless the user explicitly edits them.
- Routing is **advisory**: the user can always override the auto-picked identity in Phase 0.
