To add a rule into the PAN security rulebase you can use, replacing variables as needed:
set rulebase security rules {name} from {source-zone} to {dest-zone} souce {source} destination {destination} application any service any action allow tag {tag} group-tag {tag} log-end yes
set rulebase security rules {name} profile-setting group {spg}
set rulebase security rules {name} disabled yes