---
title: "UpdateApprovalRule"
description: "Update an approval rule"
canonical: "https://pgbeam.com/docs/go-sdk/approvals/updateApprovalRule"
last-updated: "2026-10-08T08:55:02.000Z"
---

# UpdateApprovalRule

> Update an approval rule

URL: https://pgbeam.com/docs/go-sdk/approvals/updateApprovalRule

Replaces the rule's name, statement kinds, scope, row threshold and enabled flag. An approval request already held keeps the name it was held under.

Returns 409 when the update leaves the rule enabled while the organization has a live self-hosted data plane enrollment, for the same reason as create. Setting enabled to false is still accepted.

## Usage

## Parameters

Parameter

Type

Required

Description

ctx

`context.Context`

Yes

Request context

projectID

`string`

Yes

Unique project identifier (prefixed, e.g. prj_xxx).

approvalRuleID

`string`

Yes

Unique approval rule identifier (prefixed, e.g. apl_xxx).

req

`pgbeam.ApprovalRuleInput`

Yes

Request body

req.Name

`string`

Yes

Label shown to the reviewer on every approval request this rule holds. Must be unique within the project and not blank.

req.StatementKinds

`*[]pgbeam.ApprovalRuleStatementKind`

No

Statement kinds the rule holds. Empty or omitted holds every kind.

req.SchemaName

`*string`

No

Schema to scope the rule to. Null, empty or omitted matches every schema.

req.RelationName

`*string`

No

Relation to scope the rule to. Null, empty or omitted matches every relation. Without a schema it matches that name in every schema.

req.MinAffectedRows

`*int`

No

Hold only statements affecting at least this many rows. Must be at least 1. Null or omitted holds every matching statement. The count is taken in a rolled-back trial run; a statement that reports no count (DDL, a batch, a data-modifying CTE) is held regardless.

req.Enabled

`*bool`

No

False switches the rule off, so it holds nothing.

## Response

`(*pgbeam.ApprovalRule, error)`: updated approval rule.

## Example

## Errors

Status

Description

400

The request was rejected. `code` is `INVALID_INPUT`, and `errors` names the offending fields when the failure was a validation one.

401

Missing or invalid authentication. `code` is `UNAUTHORIZED`.

403

The caller is authenticated but not allowed to perform this operation. `code` is `FORBIDDEN` when the caller's role is insufficient, and `PLAN_LIMIT_REACHED` when the organization's plan is what stands in the way. The two are answered differently, so branch on the code rather than the status.

404

The resource does not exist, or the caller is not entitled to know that it does. `code` is `NOT_FOUND`.

409

The request conflicts with the current state. `code` distinguishes the cases: `RESOURCE_EXISTS` for a name or value already in use, `INVALID_STATE` for a resource that is no longer in a state that allows the operation, and `IDEMPOTENCY_KEY_REUSED` for a retry whose body does not match the request the key was first used for.

412

The `If-Match` entity tag does not match the current representation, so the resource changed after the read this write was based on. Nothing was modified. `code` is `PRECONDITION_FAILED`. Re-read the resource, re-apply the change, and retry with the new tag.

413

The request body exceeds the 2 MB limit. `code` is `PAYLOAD_TOO_LARGE`.

415

The request body is not JSON, or carries a body without declaring a Content-Type. `code` is `UNSUPPORTED_MEDIA_TYPE`.

500

The request failed for a reason on our side. `code` is `INTERNAL_ERROR`. Quote `request_id` when reporting it.