We should add a section to the reference documentation that explains that views live within the trust boundary of the application, and the security implications thereof.