Here's my situation: we need two-factor auth for some sensitive systems, through our own SAML solution (which provides 2FA). Currently, this involves a VPN (even if you're in the office) to an internal firewall, which then provides you access to servers. If you're out of the office, which everyone is right now, it involves a VPN to the office, then connect to your desktop and VPN from there to the internal firewall, and then access those systems. It's a pain.
The idea of Teleport means that I can:
1. Have one system that gets me a shell on any of our servers, regardless of what cluster they're in or what firewall they're behind, without having to use jump hosts
2. Provide SAML/2FA authentication to our AD for all servers, not just the ones which are joined to AD
3. Eliminate shared SSH keys, password sharing, "you have to connect to host X before you can connect to host Y", and so on.
4. Enable role-based authentication across all clusters, which I can update dynamically to grant uses access to new sets of systems when and if they need them, enabling the principle of least privilege.
5. Log every session, so that we can provide an audit trail if we ever need one.
The web UI is nice because it allows quick access to all of this functionality, but it doesn't replace the command-line, and you can (and should, IMHO) keep using the command-line for most tasks. It does, however, make a much better option than tunnel after tunnel to get through firewalls to access a host to run one command.
Personally, I think teleport fantastically solves an issue that we've been banging our heads together trying to work out a good solution to, and it's pretty elegant at that.
If it doesn't make sense to you, then either you didn't read about the whole product and just saw "SSH" and "Web UI" and gave up on it immediately, or you're not in an environment where multiple layers of security, at both the application and network level, coupled with a desire for per-user or role-based access controls, create a multifaced SSH access nightmare.