The first image shows a TLOC-based route policy that directs all VPN traffic to use the Hub_TLOC_MPLS, which is exactly what's needed when branches reach the hub only over MPLS. This policy ensures that traffic from branches is routed via the MPLS circuit toward the hub site.