Rolling restarts on SHC are initiated via the Captain: `splunk rolling-restart shcluster-members`. The Captain ensures a minimum number of members remain active at all times.
Captain transfer can be forced manually: `splunk transfer shcluster-captain`. This is useful before decommissioning the current captain for maintenance.