> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.projectmanager.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.projectmanager.com/_mcp/server.

# Update Risk

PUT https://api.projectmanager.com/api/data/risks/{riskId}
Content-Type: application/json

Updates an existing Risk.
            
Only the fields provided in the request body will be updated.
Fields omitted from the request will remain unchanged.
            
Authorization is enforced to ensure the caller has access
to modify the specified Risk.

Reference: https://developer.projectmanager.com/api-reference/risk/update-risk

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Path parameters

- `riskId` (string, required) — The id of the risk

### Headers

- `x-integration-name` (string, optional) — The name of the calling system passed along as a header parameter

### Body (application/json)

This endpoint expects a RiskUpdateDto.

- `name` (string, optional, nullable) — The common name of this Risk.
- `dueDate` (string, optional, nullable) — The date when this risk is expected to be resolved.
- `percentComplete` (integer, optional, nullable) — Percentage completion (0–100).
- `priority` (integer, optional, nullable) — Priority of the risk.
- `impact` (integer, optional, nullable) — The potential effect of the risk.
- `likelihood` (integer, optional, nullable) — Probability of the risk occurring.
- `responseId` (integer, optional, nullable) — Planned or implemented response. Avoid it, Mitigate, Transfer, Accept
- `resolution` (string, optional, nullable) — Actions taken or planned to address the risk.
- `description` (string, optional, nullable) — Additional comments or observations.
- `assignees` (list of string, optional, nullable) — Users assigned to the risk. Replaces existing assignments when provided.
- `tagIds` (list of string, optional, nullable) — Tags applied to the risk. Replaces existing tags when provided.
- `riskTypeId` (integer, optional, nullable) — The type of risk. Risk = 1 Assumption = 2 Issue = 3 Dependency = 4 Change = 5
- `moveToProject` (MoveTaskToProjectDto, optional, nullable) — Object contains data to move risk to another project

## Response

### 200

Success

- `error` (AstroError, optional, nullable) — If the API call failed, this will contain information about the error that occurred.
- `success` (boolean, optional) — True if the API call succeeded; false otherwise.
- `hasError` (boolean, optional) — True if the API call failed.
- `statusCode` (enum, optional) — The HTTP code of the response.
  - Allowed values: `Continue`, `SwitchingProtocols`, `Processing`, `EarlyHints`, `OK`, `Created`, `Accepted`, `NonAuthoritativeInformation`, `NoContent`, `ResetContent`, `PartialContent`, `MultiStatus`, `AlreadyReported`, `IMUsed`, `MultipleChoices`, `MovedPermanently`, `Found`, `SeeOther`, `NotModified`, `UseProxy`, `Unused`, `TemporaryRedirect`, `PermanentRedirect`, `BadRequest`, `Unauthorized`, `PaymentRequired`, `Forbidden`, `NotFound`, `MethodNotAllowed`, `NotAcceptable`, `ProxyAuthenticationRequired`, `RequestTimeout`, `Conflict`, `Gone`, `LengthRequired`, `PreconditionFailed`, `RequestEntityTooLarge`, `RequestUriTooLong`, `UnsupportedMediaType`, `RequestedRangeNotSatisfiable`, `ExpectationFailed`, `MisdirectedRequest`, `UnprocessableEntity`, `Locked`, `FailedDependency`, `UpgradeRequired`, `PreconditionRequired`, `TooManyRequests`, `RequestHeaderFieldsTooLarge`, `UnavailableForLegalReasons`, `InternalServerError`, `NotImplemented`, `BadGateway`, `ServiceUnavailable`, `GatewayTimeout`, `HttpVersionNotSupported`, `VariantAlsoNegotiates`, `InsufficientStorage`, `LoopDetected`, `NotExtended`, `NetworkAuthenticationRequired`
- `data` (RiskDto, optional) — Represents a potential threat or uncertainty that could impact a project, system, or process. Contains information such as its likelihood, impact, response, and resolution details.

## Errors

### 400 Bad Request Error

Bad Request

- `any`

## Types

### MoveTaskToProjectDto

Move task to project data transfer object. Contains information about target project to move, necessary options and users to add access for if needed.

- `projectId` (string, optional) — Target project id to move
- `keepTimeEntries` (boolean, optional) — Move time entries associated with the task. If false, time entries will be copied to the new project but remain in the original project as well. If true, time entries will be moved to the new project and removed from the original project.
- `addAccessUserIds` (list of string, optional) — List of user IDs to add access for in the new project.

### AstroError

Information about an error that occurred within the ProjectManager API.

- `technicalError` (string, optional, nullable) — A technical description of the error that occurred. Not suitable for display to end users.
- `additionalErrors` (list of string, optional, nullable) — If additional errors beyond the main error in `Message` occurred, they will be listed here as individual messages.
- `validationErrors` (map from string to list of string, optional, nullable) — This contains a dictionary of validation errors. The key is the name of the field
- `message` (string, optional, nullable) — A description of the error that occurred. If your application has a user interface, show this message to explain what went wrong.

### RiskDto

Represents a potential threat or uncertainty that could impact a project, system, or process. Contains information such as its likelihood, impact, response, and resolution details.

- `id` (string, optional) — The unique identifier of this risk.
- `projectId` (string, optional) — The unique identifier of the Project to which this Task belongs.
- `name` (string, optional) — The common name of this Task.
- `dueDate` (string, optional, nullable) — The date when work on this risk is expected to complete. This value contains only the date in year-month-day format. For display, this date will always be shown as this same year-month-day regardless of time zone. For reporting purposes, this date is calculated against the official time zone of the Workspace.
- `percentComplete` (integer, optional) — The numerical percentage, from 0-100, representing the percentage completion for this risk. Any numbers below zero or above 100 will be clamped to the minimum or maximum value.
- `priority` (integer, optional, nullable) — Indicates the level of importance assigned to a risk, with 500 being standard priority; the higher the number, the higher the priority.
- `impact` (integer, optional, nullable) — The potential effect of the risk.
- `likelihood` (integer, optional, nullable) — Probability or chance of the risk occurring.
- `responseId` (integer, optional, nullable) — The planned or implemented response to address the identified risk. Avoid, Mitigate, Transfer, Accept
- `resolution` (string, optional, nullable) — The actions or strategy planned or taken to mitigate or eliminate the risk.
- `notes` (string, optional, nullable) — Any additional comments, observations, or details related to the risk.
- `createDate` (string, optional) — The timestamp in UTC when this risk was created.
- `modifyDate` (string, optional) — The timestamp in UTC when this risk was most recently modified.
- `version` (integer, optional) — The risk version.
- `shortId` (string, optional, nullable) — A short ID that can be used to refer to this risk. This short ID is guaranteed to be unique within your Workspace.
- `taskTypeId` (integer, optional) — Risk has a taskTypeId of 31
- `assignments` (list of RiskAssignmentDto, optional) — Users assigned to the risk.
- `tags` (list of TaskTagDto, optional) — Tags applied to the risk.
- `owner` (TaskOwnerDto, optional) — The user which created the risk.
- `filesCount` (integer, optional, nullable) — The number of files attached to the risk.
- `commentsCount` (integer, optional, nullable) — The number of comments added to the risk.
- `riskTypeId` (integer, optional) — The id of the Risk Type Risk = 1 Assumption = 2 Issue = 3 Dependency = 4 Change = 5
- `project` (RiskProjectDto, optional, nullable) — The Project to which this Risk belongs.

### RiskAssignmentDto

User assigned to task or risk

- `taskId` (string, optional) — Task or risk the user is assigned to
- `projectId` (string, optional, nullable) — The task or risk project Id
- `resourceId` (string, optional) — Resource identifier

### TaskTagDto

A TaskTag is a connection between a Task and a Tag. Each Task can have zero, one or many TaskTags associated with it. TaskTags can be assigned and removed from the Task to help you classify your Tasks and prioritize work.

- `id` (string, optional) — The unique identifier of this TaskTag.
- `name` (string, optional) — The common name of this TaskTag.
- `color` (string, optional) — The color that will be used to represent this Tag visually. This color is automatically chosen by the application when a user creates a Tag. You can choose specify any color that can be represented using HTML RGB syntax such as `#0088FF`, in the format `RRGGBB`. You may not use names for colors.

### TaskOwnerDto

A Resource represents a person, material, or tool that is used within your Projects. When you attach a Resources to more than one Task, the software will schedule the usage of your Resource so that it is not allocated to more than one Task at the same time. The users in your Workspace are also considered Resources. To invite a new User to your Workspace, create a new Resource for that user.

- `id` (string, optional) — The unique identifier of this Resource.
- `initials` (string, optional) — The resource initials.
- `name` (string, optional, nullable) — Display name for this Resource.
- `shortName` (string, optional, nullable) — Short display name for this Resource.
- `firstName` (string, optional, nullable) — The first name of the person Resource. Applies to personnel Resources only.
- `lastName` (string, optional, nullable) — The last name of the person Resource. Applies to personnel Resources only.
- `email` (string, optional, nullable) — If this Resource is a person who can log on to ProjectManager.com, this value should be the email address of the person. If this Resource is not a person, but you wish to receive email alerts for usage of this Resource, you can also add an email address here and notifications will be sent when this Resource is used. Otherwise this value should be `null`.
- `isActive` (boolean, optional) — True if this Resource is currently active and valid. If this value is false, this Resource is considered to be deactivated and not available for further use. For personnel Resources, setting this value to False will make this user unable to access this Workspace.
- `color` (string, optional, nullable) — Read only Hex code of the ColorName
- `avatarUrl` (string, optional, nullable) — The resources avatar url, if any.

### RiskProjectDto

A Project is a collection of Tasks that contributes towards a goal. Within a Project, Tasks represent individual items of work that team members must complete. The sum total of Tasks within a Project represents the work to be completed for that Project.

- `id` (string, optional) — The unique identifier of this Project.
- `shortId` (string, optional) — The ShortId of this Project.
- `name` (string, optional) — The common name of this Project.

## Examples

**Request**

```json
{}
```

**Response**

```json
{
  "error": {
    "technicalError": "string",
    "additionalErrors": [
      "string"
    ],
    "validationErrors": {},
    "message": "string"
  },
  "success": true,
  "hasError": true,
  "statusCode": "Continue",
  "data": {
    "id": "string",
    "projectId": "string",
    "name": "string",
    "dueDate": "2023-01-15",
    "percentComplete": 1,
    "priority": 1,
    "impact": 1,
    "likelihood": 1,
    "responseId": 1,
    "resolution": "string",
    "notes": "string",
    "createDate": "2024-01-15T09:30:00Z",
    "modifyDate": "2024-01-15T09:30:00Z",
    "version": 1,
    "shortId": "string",
    "taskTypeId": 1,
    "assignments": [
      {
        "taskId": "string",
        "projectId": "string",
        "resourceId": "string"
      }
    ],
    "tags": [
      {
        "id": "string",
        "name": "string",
        "color": "string"
      }
    ],
    "owner": {
      "id": "string",
      "initials": "string",
      "name": "string",
      "shortName": "string",
      "firstName": "string",
      "lastName": "string",
      "email": "string",
      "isActive": true,
      "color": "string",
      "avatarUrl": "string"
    },
    "filesCount": 1,
    "commentsCount": 1,
    "riskTypeId": 1,
    "project": {
      "id": "string",
      "shortId": "string",
      "name": "string"
    }
  }
}
```

**SDK Code**

```python
import requests

url = "https://api.projectmanager.com/api/data/risks/riskId"

payload = {}
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.put(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.projectmanager.com/api/data/risks/riskId';
const options = {
  method: 'PUT',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.projectmanager.com/api/data/risks/riskId"

	payload := strings.NewReader("{}")

	req, _ := http.NewRequest("PUT", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.projectmanager.com/api/data/risks/riskId")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Put.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.put("https://api.projectmanager.com/api/data/risks/riskId")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('PUT', 'https://api.projectmanager.com/api/data/risks/riskId', [
  'body' => '{}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.projectmanager.com/api/data/risks/riskId");
var request = new RestRequest(Method.PUT);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.projectmanager.com/api/data/risks/riskId")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "PUT"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```