Blog/ Outlook how-tos

Outlook Folder Permission Levels Explained: Reviewer to Owner

Nafiul HasanNafiul Hasan· 8 min read
Diagram comparing all nine Outlook folder permission levels from Reviewer up to Owner

The short answer

Outlook's folder permission levels are fixed bundles, not individual checkboxes: Reviewer only reads, Contributor only creates, Author and Nonediting Author edit or delete just their own items, Editor and Publishing Editor can edit and delete everything, and Owner also controls other people's permissions. Publishing Editor and Publishing Author additionally let someone create subfolders.

Outlook folder permission levels explained: what Owner, Editor, Author, Reviewer and Contributor let someone do, and the subfolder rule people miss.

On this page
  1. 01How Outlook Permission Levels Actually Work
  2. 02Why the Right Level Matters
  3. 03Outlook Folder Permission Levels Compared
  4. 04Common Misconceptions About Outlook Folder Permissions
  5. 05How This Shows Up in AI Emaily

Outlook folder permission levels explained simply: each one is a fixed bundle of rights that Exchange applies together, not something you build one checkbox at a time. Reviewer means read-only. Contributor means create-only, with no ability to even see what's already in the folder. Author lets someone create and manage their own items but not touch anyone else's. Editor and every level above it can touch every item in the folder, including deleting mail someone else put there.

That asymmetry is exactly what trips people up. Editor can delete something Author created; Author can't touch anything that isn't theirs, even on a folder they've had access to for years. Assign the wrong level and you either lock a colleague out of work they're meant to be doing, or hand them delete rights over a folder they were only ever supposed to review.

How Outlook Permission Levels Actually Work#

Right-click any folder in Outlook — the classic desktop app, new Outlook, or Outlook on the web — choose Properties (or Access permissions / Sharing and permissions on the web), then open the Permissions tab. A Permission Level dropdown sets nine standard levels in one move: Owner, Publishing Editor, Editor, Publishing Author, Author, Nonediting Author, Reviewer, Contributor, and None. Pick one and Outlook fills in every underlying checkbox for you.

Those checkboxes are what actually get enforced — the dropdown is just a shortcut to a common combination of them. Under the hood there's a Create items switch, a Create subfolders switch, an Edit items setting (none, own items, or all items), and a Delete items setting with the same three options, plus Folder owner, Folder contact and Folder visible flags in an Other section. Change any one of them after choosing a preset, and the dropdown quietly relabels itself Custom. That's expected behavior, not a bug — it's how you'd build something like "can create and edit, but never delete."

The same mechanism covers any folder in a mailbox — Inbox, a project folder you created yourself, Tasks, Contacts, Calendar. It's the same permission engine Outlook uses for delegate access, though delegate access wraps it in its own dialog (Account Settings, Delegate Access) layered with Send on Behalf Of and, for Calendar specifically, a couple of free/busy-only detail levels covered in the FAQ below.

Illustration of toggle switches representing how each Outlook permission level bundles create, edit, delete and subfolder rights together
A permission level is several individual rights switched on or off together, not one access flag.

Why the Right Level Matters#

Pick too low a level and someone can't do their job. Give Contributor to a person who's supposed to triage a shared intake folder, and they can drop new items in but can't read anything already sitting there — Contributor is create-only, full stop. Give Reviewer to someone who needs to update a shared project folder, and every edit they try simply won't save.

Pick too high a level and you've handed out delete rights nobody asked for. Editor and Publishing Editor can remove any item in the folder, including ones they didn't create. On a shared Sent Items folder or a team's client folder, that's a real risk to run for no reason — the fix is almost never Editor, it's Author or Publishing Author, which cover create-and-manage-your-own without touching what belongs to other people.

A common real-world case: a manager shares a "Client Correspondence" folder with three account reps and sets everyone to Editor so nobody's blocked. Six months later, someone notices a client email is missing — not because it was deleted maliciously, but because a rep cleaning up their own filed copies had rights over the whole folder and didn't realize it. Author or Publishing Author would have let each rep manage their own filed mail without ever touching a colleague's.

The subfolder people always miss

Permission doesn't cascade down a folder tree. Giving someone Editor on a subfolder does nothing if they don't also have at least Folder Visible permission on every folder above it in the path — without that, the subfolder simply never appears in their folder list, even though their access to it is technically correct.

Outlook Folder Permission Levels Compared#

Nine standard levels cover every folder type outside Calendar's two extra free/busy-only options. Here is exactly what each one allows, matched to Microsoft's own definitions:

LevelCreate itemsRead itemsEdit / delete scopeCreate subfoldersManage permissions
OwnerYesYesEdit and delete every itemYesYes
Publishing EditorYesYesEdit and delete every itemYesNo
EditorYesYesEdit and delete every itemNoNo
Publishing AuthorYesYesEdit and delete only items you createdYesNo
AuthorYesYesEdit and delete only items you createdNoNo
Nonediting AuthorYesYesDelete only items you created — no editingNoNo
ReviewerNoYesNoneNoNo
ContributorYesNoNoneNoNo
NoneNoNoNoneNoNo

Common Misconceptions About Outlook Folder Permissions#

  • "Editor and Author are basically the same." They're not: Editor can edit and delete every item in the folder; Author can only touch items they personally created. Give Editor to a genuine co-manager, Author to a contributor.
  • "Publishing means it's for approving or publishing content." The word only refers to subfolder creation. Publishing Editor is Editor plus the ability to create subfolders; Publishing Author is Author plus the same. Neither adds any kind of approval step.
  • "Reviewer permission lets someone leave a note or flag an item." Reviewer is strictly read-only — no create, no edit, not even on their own annotations. There's no lightweight comment tier in Outlook's permission model.
  • "Sharing my Inbox shares my whole mailbox." Each folder keeps its own separate permission list. Giving someone access to your Inbox says nothing about your Contacts, Tasks, or Sent Items — set each one you actually want to share.
  • "None means the folder is invisible." None means they can't open it or read anything inside. Whether it even shows up in their folder list at all is a separate setting — Folder Visible — not part of the None level itself.
  • "Changing the permission level updates instantly for the other person." It usually takes effect the next time their Outlook client syncs with the server, not the moment you click OK. On a slow connection or with Outlook set to work offline, that can be several minutes — worth knowing before you assume a permission change didn't work.

How This Shows Up in AI Emaily#

None of this changes when you connect an Outlook account to AI Emaily. If Outlook already has you looking at a shared or delegated folder — because someone gave you Editor on a team intake folder, or Reviewer on their Sent Items — that same scope is what we read through Microsoft's Graph API; connecting the account doesn't grant, widen, or bypass a single right that Outlook's own permission list doesn't already give you. What it adds is one inbox where that shared folder sits next to your own accounts, with drafts routed through Copilot's approve-before-send step rather than going out from a shared mailbox unnoticed, and an audit log so a folder with several Editors stays traceable to who — or what — actually touched a message. We build AI Emaily.

Frequently asked

Nafiul Hasan

Written by

Nafiul Hasan

Nafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.

EntrepreneurAI Automation System BuilderAI EnthusiastBuilds AI Enterprise Solutions10+ years experience
More from Nafiul
Ready when you are

Bring every shared Outlook folder into one inbox

Connect your Outlook accounts to AI Emaily and see delegated and shared mail next to your own — with approvals and an audit trail on top of whatever access Outlook already granted.

  • 7-day free trial
  • Cancel anytime
  • Every provider