When I set a custom Permission on an Instance's Security Page, it shows up in the Instance Editor

(Bug, Investigate , Priority: High, Test Status: No automated tests yet , Reported By Justin du Coeur, )
Summary: That is, if I add a Person or Role to a custom Who Can Edit, then Who Can Edit shows up in the Instance Editor. It shouldn't -- this should only be in Security.
Do we already have a "do not edit" flag that works for this? I suppose we could use setInternal, although I worry that might be overkill for Permissions.