A rule is applied to a user action in an online environment to produce a result. The user action is by a second user and a first user is subject to the user action, or the user action is by the first user in response to a prior action by the second user. Based on the result of the applying indicating to do so, a score is determined (502-514) based at least: a first value corresponding to the rule, and a second value based on past actions in the online environment between the first user and the second user using action information relating to the second user stored in an action log of the first user. It is then determined(516)if an intervention action against the second user is to be taken based at least on the score. The intervention action may then be taken (518).